8.8
CVE-2013-5461
- EPSS 2.36%
- Veröffentlicht 27.04.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 01:57:31
- Erkennungen
IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Endpoint Manager For Remote Control Version 9.0.0
Ibm ≫ Endpoint Manager For Remote Control Version 9.0.1
Ibm ≫ Tivoli Remote Control Version 5.1.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.36% | 0.817 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
https://exchange.xforce.ibmcloud.com/vulnerabilities/88309
https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwords-in-ibm-endpoint-manager-for-remote-control-cve-2013-5461/
https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwords-in-tivoli-remote-control-cve-2013-5461/