VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain login access by leveraging knowledge of a password hash.
References
Configurations
Information
Published : 2015-01-08 07:59
Updated : 2017-03-06 18:59
NVD link : CVE-2014-9578
Mitre link : CVE-2014-9578
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
vdgsecurity
- vdg_sense