Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail messages, which allows remote attackers to obtain the cleartext NIS password hashes.
References
| Link | Resource |
|---|---|
| http://marc.info/?l=bugtraq&m=112818351032426&w=2 | Mailing List Third Party Advisory |
| http://secunia.com/advisories/17033/ | Broken Link Vendor Advisory |
| http://www.securityfocus.com/bid/14997 | Broken Link Third Party Advisory VDB Entry |
| http://marc.info/?l=bugtraq&m=112818351032426&w=2 | Mailing List Third Party Advisory |
| http://secunia.com/advisories/17033/ | Broken Link Vendor Advisory |
| http://www.securityfocus.com/bid/14997 | Broken Link Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2005-10-05 21:02
Updated : 2025-04-03 01:03
NVD link : CVE-2005-3140
Mitre link : CVE-2005-3140
CVE.ORG link : CVE-2005-3140
JSON object : View
Products Affected
procom
- netforce_800_firmware
- netforce_800
CWE
CWE-319
Cleartext Transmission of Sensitive Information
