Описание
NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a "network breakin" event, which allows local users to obtain passwords by reading the file.
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- Patch
- Vendor Advisory
- PatchVendor Advisory
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:dec:dec_openvms_alpha:7.3.2:*:*:*:*:*:*:*
cpe:2.3:a:dec:dec_openvms_alpha:8.2:*:*:*:*:*:*:*
EPSS
Процентиль: 22%
0.00074
Низкий
2.1 Low
CVSS2
Дефекты
CWE-200
Связанные уязвимости
github
почти 4 года назад
NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a "network breakin" event, which allows local users to obtain passwords by reading the file.
EPSS
Процентиль: 22%
0.00074
Низкий
2.1 Low
CVSS2
Дефекты
CWE-200