Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2001-1106

Опубликовано: 25 июл. 2001
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sambar:sambar_server:4.1:*:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:4.2.1_production:*:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:4.3:*:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:4.4:*:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.0:beta1:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.0:beta2:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.0:beta3:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.0:beta4:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.0:beta5:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.01461
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.

EPSS

Процентиль: 80%
0.01461
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other