Lucene search

K
cveRedhatCVE-2013-1941
HistoryJun 04, 2014 - 2:55 p.m.

CVE-2013-1941

2014-06-0414:55:03
CWE-310
redhat
web.nvd.nist.gov
27
owncloud
server
installation routine
vulnerability
postgresql
database
password
brute force
attack
cve-2013-1941

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

51.9%

The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time function to seed the generation of the PostgreSQL database user password, which makes it easier for remote attackers to guess the password via a brute force attack.

Affected configurations

Nvd
Node
owncloudowncloudRange4.0.13
OR
owncloudowncloudMatch4.0.0
OR
owncloudowncloudMatch4.0.1
OR
owncloudowncloudMatch4.0.2
OR
owncloudowncloudMatch4.0.3
OR
owncloudowncloudMatch4.0.4
OR
owncloudowncloudMatch4.0.5
OR
owncloudowncloudMatch4.0.6
OR
owncloudowncloudMatch4.0.7
OR
owncloudowncloudMatch4.0.8
OR
owncloudowncloudMatch4.0.9
OR
owncloudowncloudMatch4.0.10
OR
owncloudowncloudMatch4.0.11
OR
owncloudowncloudMatch4.0.12
Node
owncloudowncloudMatch4.5.0
OR
owncloudowncloudMatch4.5.1
OR
owncloudowncloudMatch4.5.2
OR
owncloudowncloudMatch4.5.3
OR
owncloudowncloudMatch4.5.4
OR
owncloudowncloudMatch4.5.5
OR
owncloudowncloudMatch4.5.6
OR
owncloudowncloudMatch4.5.7
OR
owncloudowncloudMatch4.5.8
Node
owncloudowncloudMatch5.0.0
OR
owncloudowncloudMatch5.0.1
OR
owncloudowncloudMatch5.0.2
OR
owncloudowncloudMatch5.0.3
VendorProductVersionCPE
owncloudowncloud*cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*
owncloudowncloud4.0.0cpe:2.3:a:owncloud:owncloud:4.0.0:*:*:*:*:*:*:*
owncloudowncloud4.0.1cpe:2.3:a:owncloud:owncloud:4.0.1:*:*:*:*:*:*:*
owncloudowncloud4.0.2cpe:2.3:a:owncloud:owncloud:4.0.2:*:*:*:*:*:*:*
owncloudowncloud4.0.3cpe:2.3:a:owncloud:owncloud:4.0.3:*:*:*:*:*:*:*
owncloudowncloud4.0.4cpe:2.3:a:owncloud:owncloud:4.0.4:*:*:*:*:*:*:*
owncloudowncloud4.0.5cpe:2.3:a:owncloud:owncloud:4.0.5:*:*:*:*:*:*:*
owncloudowncloud4.0.6cpe:2.3:a:owncloud:owncloud:4.0.6:*:*:*:*:*:*:*
owncloudowncloud4.0.7cpe:2.3:a:owncloud:owncloud:4.0.7:*:*:*:*:*:*:*
owncloudowncloud4.0.8cpe:2.3:a:owncloud:owncloud:4.0.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 271

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

51.9%