6.6
CVE-2017-6911
- EPSS 0.58%
- Veröffentlicht 23.03.2017 20:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according his own requirements that may aid in further attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Usb Pratirodh Project ≫ Usb Pratirodh Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.58% | 0.428 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.6 | 0.7 | 5.9 |
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-922 Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
http://packetstormsecurity.com/files/141651/USB-Pratirodh-Insecure-Password-Storage.html
http://seclists.org/fulldisclosure/2017/Mar/43
http://www.securityfocus.com/archive/1/540289/100/0/threaded
http://www.securityfocus.com/bid/96970