7.5

CVE-2008-3289

EMC Dantz Retrospect Backup Client 7.5.116 sends the password hash in cleartext at an unspecified point, which allows remote attackers to obtain sensitive information via a crafted packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
StorcentricRetrospect Backup Client Version7.5.116 SwPlatform-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.24% 0.915
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

http://kb.dantz.com/display/2/articleDirect/index.asp?aid=9692&r=0.5160639
Broken Link
http://secunia.com/advisories/31186
Patch
Vendor Advisory
Broken Link
http://www.fortiguardcenter.com/advisory/FGA-2008-16.html
Patch
Broken Link
http://www.vupen.com/english/advisories/2008/2150/references
Broken Link
http://securityreason.com/securityalert/4025
Third Party Advisory
http://www.securityfocus.com/archive/1/494560/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/30308
Patch
Third Party Advisory
Broken Link
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/43930
Third Party Advisory
VDB Entry