Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-286j-4758-jr9w

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.

The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.

EPSS

Процентиль: 77%
0.01063
Низкий

Связанные уязвимости

nvd
почти 24 года назад

The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.

EPSS

Процентиль: 77%
0.01063
Низкий