In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved by any user with access to the PACTware workstation.
En PACTware versiones anteriores a 4.1 SP6 y versiones 5.x anteriores a 5.0.5.31, las contraseñas son almacenadas en un formato recuperable y pueden ser recuperadas por cualquier usuario con acceso a la estación de trabajo de PACTware
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | NONE |
| Availability Impact | NONE |
AV:L/AC:L/Au:N/C:P/I:N/A:N
| Access Vector | LOCAL |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | NONE |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-522
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| pactware | pactware | * | <built-in method update of dict object at 0x7e6107e46dc0> | Application |
| pactware | pactware | 2.4 | <built-in method update of dict object at 0x7e610742e240> | Application |
| pactware | pactware | 3.0 | <built-in method update of dict object at 0x7e610742d0c0> | Application |
| pactware | pactware | 3.5 | <built-in method update of dict object at 0x7e60a888c980> | Application |
| pactware | pactware | 3.6 | <built-in method update of dict object at 0x7e6107e44380> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:pactware:pactware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:pactware:pactware:2.4:sp4:*:*:*:*:*:* |
| Yes | cpe:2.3:a:pactware:pactware:3.0:sp5:*:*:*:*:*:* |
| Yes | cpe:2.3:a:pactware:pactware:3.5:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:pactware:pactware:3.6:sp1:*:*:*:*:*:* |