Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" option is used, stores the password with a weak encryption scheme (one-to-one mapping) in a registry key, which allows local users to obtain and decrypt the password.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2002-10/0438.html | Broken Link |
http://www.iss.net/security_center/static/10517.php | Broken Link |
Configurations
History
No history.
Information
Published : 2002-12-31 05:00
Updated : 2024-02-14 15:50
NVD link : CVE-2002-1946
Mitre link : CVE-2002-1946
CVE.ORG link : CVE-2002-1946
JSON object : View
Products Affected
tata
- integrated_dialer
CWE
CWE-326
Inadequate Encryption Strength