2.1

CVE-2006-4537

NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a "network breakin" event, which allows local users to obtain passwords by reading the file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DecDec Openvms Alpha Version7.3.2
DecDec Openvms Alpha Version8.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.45
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIECO03-V732.txt
ftp://ftp.itrc.hp.com/openvms_patches/alpha/V8.2/AXP_DNVOSIECO02-V82.txt
http://secunia.com/advisories/21705
Patch
Vendor Advisory
http://secunia.com/advisories/23632
Vendor Advisory
http://securitytracker.com/id?1016772
http://securitytracker.com/id?1017472
http://www.osvdb.org/28272
http://www.securityfocus.com/bid/19783
Patch
http://www.vupen.com/english/advisories/2006/3423
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/28695