5

CVE-2014-3503

Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Syncope Version 1.1.0
Apache ≫ Syncope Version 1.1.1
Apache ≫ Syncope Version 1.1.2
Apache ≫ Syncope Version 1.1.3
Apache ≫ Syncope Version 1.1.4
Apache ≫ Syncope Version 1.1.5
Apache ≫ Syncope Version 1.1.6
Apache ≫ Syncope Version 1.1.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.97% 0.924
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://syncope.apache.org/security.html
Vendor Advisory
http://packetstormsecurity.com/files/127375/Apache-Syncope-Insecure-Password-Generation.html
http://www.securityfocus.com/archive/1/532669/100/0/threaded
http://www.securityfocus.com/bid/68431