In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by an attacker with no knowledge of the current passwords.
En PACTware versiones anteriores a 4.1 SP6 y versiones 5.x anteriores a 5.0.5.31, las contraseñas son almacenadas de manera no segura y pueden ser modificadas por parte de un atacante sin conocimiento de las contraseñas actuales
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | NONE |
AV:L/AC:L/Au:N/C:P/I:P/A:N
| Access Vector | LOCAL |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | PARTIAL |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-522
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| pactware | pactware | * | <built-in method update of dict object at 0x7e60a88afa80> | Application |
| pactware | pactware | 2.4 | <built-in method update of dict object at 0x7e60a888e1c0> | Application |
| pactware | pactware | 3.0 | <built-in method update of dict object at 0x7e60a88ada80> | Application |
| pactware | pactware | 3.5 | <built-in method update of dict object at 0x7e611232c340> | Application |
| pactware | pactware | 3.6 | <built-in method update of dict object at 0x7e60a88ae3c0> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:pactware:pactware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:pactware:pactware:2.4:sp5:*:*:*:*:*:* |
| Yes | cpe:2.3:a:pactware:pactware:3.0:sp4:*:*:*:*:*:* |
| Yes | cpe:2.3:a:pactware:pactware:3.5:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:pactware:pactware:3.6:sp1:*:*:*:*:*:* |