Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3cwv-qrjg-9hf5

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.

Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.

EPSS

Процентиль: 16%
0.00051
Низкий

Связанные уязвимости

nvd
около 21 года назад

Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.

EPSS

Процентиль: 16%
0.00051
Низкий