| |
Vulnerability CVE-2004-1709
Published: 2004-08-04 Modified: 2012-02-12
Description: |
Datakey Rainbow iKey2032 USB token, when using the CIP client package, does not encrypt communications between the token and the driver, which could allow local users to obtain the PINs of other users. |
CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
2.1/10 |
2.9/10 |
3.9/10 |
Exploit range |
Attack complexity |
Authentication |
Local |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
http://xforce.iss.net/xforce/xfdb/16887
http://marc.theaimsgroup.com/?l=bugtraq&m=109164096013467&w=2
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|