VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain usernames and password hashes by logging in to TCP port 51410 and reading the response.
References
Configurations
Information
Published : 2015-01-08 07:59
Updated : 2015-01-08 11:50
NVD link : CVE-2014-9577
Mitre link : CVE-2014-9577
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
vdgsecurity
- vdg_sense