USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according his own requirements that may aid in further attack.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Mar/43 | Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/141651/USB-Pratirodh-Insecure-Password-Storage.html | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/96970 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/archive/1/540289/100/0/threaded |
Configurations
Information
Published : 2017-03-23 13:59
Updated : 2019-10-02 17:03
NVD link : CVE-2017-6911
Mitre link : CVE-2017-6911
JSON object : View
CWE
CWE-922
Insecure Storage of Sensitive Information
Products Affected
usb_pratirodh_project
- usb_pratirodh