CVE-2005-3140

Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail messages, which allows remote attackers to obtain the cleartext NIS password hashes.
References
Link Resource
http://marc.info/?l=bugtraq&m=112818351032426&w=2 Mailing List Third Party Advisory
http://secunia.com/advisories/17033/ Broken Link Vendor Advisory
http://www.securityfocus.com/bid/14997 Broken Link Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:procom:netforce_800_firmware:4.02:m10:*:*:*:*:*:*
cpe:2.3:h:procom:netforce_800:-:*:*:*:*:*:*:*

History

25 Jan 2024, 20:58

Type Values Removed Values Added
CVSS v2 : 5.0
v3 : unknown
v2 : 5.0
v3 : 7.5
References () http://marc.info/?l=bugtraq&m=112818351032426&w=2 - () http://marc.info/?l=bugtraq&m=112818351032426&w=2 - Mailing List, Third Party Advisory
References () http://secunia.com/advisories/17033/ - Vendor Advisory () http://secunia.com/advisories/17033/ - Broken Link, Vendor Advisory
References () http://www.securityfocus.com/bid/14997 - () http://www.securityfocus.com/bid/14997 - Broken Link, Third Party Advisory, VDB Entry
CPE cpe:2.3:a:procom_technology:netforce:800_4.2_m10_build20:*:*:*:*:*:*:* cpe:2.3:h:procom:netforce_800:-:*:*:*:*:*:*:*
cpe:2.3:o:procom:netforce_800_firmware:4.02:m10:*:*:*:*:*:*
First Time Procom netforce 800
Procom netforce 800 Firmware
Procom
CWE NVD-CWE-Other CWE-319

Information

Published : 2005-10-05 21:02

Updated : 2024-01-25 20:58


NVD link : CVE-2005-3140

Mitre link : CVE-2005-3140

CVE.ORG link : CVE-2005-3140


JSON object : View

Products Affected

procom

  • netforce_800
  • netforce_800_firmware
CWE
CWE-319

Cleartext Transmission of Sensitive Information