Lucene search

K
cveMitreCVE-2003-1439
HistoryOct 23, 2007 - 1:00 a.m.

CVE-2003-1439

2007-10-2301:00:00
CWE-255
mitre
web.nvd.nist.gov
21
silc
vulnerability
password storage
plaintext
memory
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

55.3%

Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information.

Affected configurations

Nvd
Node
silcsecure_internet_live_conferencingMatch0.9.11
OR
silcsecure_internet_live_conferencingMatch0.9.12
VendorProductVersionCPE
silcsecure_internet_live_conferencing0.9.11cpe:2.3:a:silc:secure_internet_live_conferencing:0.9.11:*:*:*:*:*:*:*
silcsecure_internet_live_conferencing0.9.12cpe:2.3:a:silc:secure_internet_live_conferencing:0.9.12:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

55.3%

Related for CVE-2003-1439