VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain usernames and password hashes by logging in to TCP port 51410 and reading the response.
References
Configurations
Information
Published : 2015-01-08 15:59
Updated : 2015-01-08 19:50
NVD link : CVE-2014-9577
Mitre link : CVE-2014-9577
JSON object : View
Products Affected
vdgsecurity
- vdg_sense
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
