CVE-2005-3140

Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail messages, which allows remote attackers to obtain the cleartext NIS password hashes.
References
Link Resource
http://marc.info/?l=bugtraq&m=112818351032426&w=2 Mailing List Third Party Advisory
http://secunia.com/advisories/17033/ Broken Link Vendor Advisory
http://www.securityfocus.com/bid/14997 Broken Link Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:procom:netforce_800_firmware:4.02:m10:*:*:*:*:*:*
cpe:2.3:h:procom:netforce_800:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2005-10-05 21:02

Updated : 2024-01-25 20:58


NVD link : CVE-2005-3140

Mitre link : CVE-2005-3140

CVE.ORG link : CVE-2005-3140


JSON object : View

Products Affected

procom

  • netforce_800_firmware
  • netforce_800
CWE
CWE-319

Cleartext Transmission of Sensitive Information