Описание
Spectrum Cash Receipting System before 6.504 uses weak cryptography (static substitution) in the PASSFILE password file, which makes it easier for local users to gain privileges by decrypting a password.
Ссылки
- Mailing List
- Broken LinkVendor Advisory
- Broken Link
- Mailing List
- Broken LinkVendor Advisory
- Broken Link
Уязвимые конфигурации
Конфигурация 1Версия до 6.504 (исключая)
cpe:2.3:a:spectrumcu:cash_receipting_system:*:*:*:*:*:*:*:*
EPSS
Процентиль: 20%
0.00064
Низкий
7.8 High
CVSS3
6.9 Medium
CVSS2
Дефекты
CWE-327
Связанные уязвимости
CVSS3: 7.8
github
почти 4 года назад
Spectrum Cash Receipting System before 6.504 uses weak cryptography (static substitution) in the PASSFILE password file, which makes it easier for local users to gain privileges by decrypting a password.
EPSS
Процентиль: 20%
0.00064
Низкий
7.8 High
CVSS3
6.9 Medium
CVSS2
Дефекты
CWE-327