Lucene search

K
cve[email protected]CVE-2008-3147
HistoryJul 11, 2008 - 7:41 p.m.

CVE-2008-3147

2008-07-1119:41:00
CWE-200
web.nvd.nist.gov
27
wefi
access-point keys
cleartext
information security
vulnerability

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

WeFi 3.2.1.4.1, when diagnostic mode is enabled, stores (1) WEP, (2) WPA, and (3) WPA2 access-point keys in (a) ClientWeFiLog.dat, (b) ClientWeFiLog.bak, and possibly © a certain .inf file under %PROGRAMFILES%\WeFi\Users, and uses cleartext for the ClientWeFiLog files, which allows local users to obtain sensitive information by reading these files.

Affected configurations

NVD
Node
wefiwefiMatch3.2.1.4.1
CPENameOperatorVersion
wefi:wefiwefieq3.2.1.4.1

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2008-3147