Lucene search

K
cveIbmCVE-2013-5461
HistoryApr 27, 2018 - 4:29 p.m.

CVE-2013-5461

2018-04-2716:29:00
CWE-255
ibm
web.nvd.nist.gov
22
ibm
endpoint manager
remote control
tivoli
security vulnerability
password decryption
cve-2013-5461
nvd
ibm x-force

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.002

Percentile

61.4%

IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.

Affected configurations

Nvd
Node
ibmendpoint_manager_for_remote_controlMatch9.0.0
OR
ibmendpoint_manager_for_remote_controlMatch9.0.1
Node
ibmtivoli_remote_controlMatch5.1.2
VendorProductVersionCPE
ibmendpoint_manager_for_remote_control9.0.0cpe:2.3:a:ibm:endpoint_manager_for_remote_control:9.0.0:*:*:*:*:*:*:*
ibmendpoint_manager_for_remote_control9.0.1cpe:2.3:a:ibm:endpoint_manager_for_remote_control:9.0.1:*:*:*:*:*:*:*
ibmtivoli_remote_control5.1.2cpe:2.3:a:ibm:tivoli_remote_control:5.1.2:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.002

Percentile

61.4%

Related for CVE-2013-5461