Vulnerability CVE-2017-6911


Published: 2017-03-23

Description:
USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according his own requirements that may aid in further attack.

Type:

CWE-922

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Usb pratirodh project -> Usb pratirodh 

 References:
http://packetstormsecurity.com/files/141651/USB-Pratirodh-Insecure-Password-Storage.html
http://seclists.org/fulldisclosure/2017/Mar/43
http://www.securityfocus.com/archive/1/540289/100/0/threaded
http://www.securityfocus.com/bid/96970

Copyright 2024, cxsecurity.com

 

Back to Top