Lucene search

K
cveMitreCVE-2006-4537
HistorySep 05, 2006 - 6:04 p.m.

CVE-2006-4537

2006-09-0518:04:00
CWE-200
mitre
web.nvd.nist.gov
22
cve-2006-4537
decnet-plus
openvms
security vulnerability
password exposure
audit log

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

25.6%

NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a “network breakin” event, which allows local users to obtain passwords by reading the file.

Affected configurations

Nvd
Node
decdec_openvms_alphaMatch7.3.2
OR
decdec_openvms_alphaMatch8.2
VendorProductVersionCPE
decdec_openvms_alpha7.3.2cpe:2.3:a:dec:dec_openvms_alpha:7.3.2:*:*:*:*:*:*:*
decdec_openvms_alpha8.2cpe:2.3:a:dec:dec_openvms_alpha:8.2:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

25.6%

Related for CVE-2006-4537