Lucene search

K
cveMitreCVE-2006-5303
HistoryOct 17, 2006 - 3:07 p.m.

CVE-2006-5303

2006-10-1715:07:00
mitre
web.nvd.nist.gov
29
cve-2006-5303
secure computing safeword
remoteaccess
information security
vulnerability
third party information
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

Secure Computing SafeWord RemoteAccess 2.1 allows local users to obtain the UserCenter webportal password, database encryption keys, and signing keys by reading (1) base-64 encoded data in SERVERS\Web\Tomcat\usercenter\WEB-INF\login.conf and (2) plaintext data in SERVERS\Shared\signers.cfg. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Affected configurations

Nvd
Node
securecomputingsafeword_remoteaccessMatch2.1
VendorProductVersionCPE
securecomputingsafeword_remoteaccess2.1cpe:2.3:a:securecomputing:safeword_remoteaccess:2.1:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2006-5303