cvelist/2014/4xxx/CVE-2014-4623.json
2019-03-17 23:13:41 +00:00

82 lines
2.8 KiB
JSON

{
"CVE_data_meta": {
"ASSIGNER": "security_alert@emc.com",
"ID": "CVE-2014-4623",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Hardening before 2.0.0.4 is enabled, uses UNIX DES crypt for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "70732",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/70732"
},
{
"name": "emc-avamar-cve20144623-info-disc(97757)",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/97757"
},
{
"name": "1031117",
"refsource": "SECTRACK",
"url": "http://www.securitytracker.com/id/1031117"
},
{
"name": "20141022 ESA-2014-094: EMC Avamar Weak Password Storage Vulnerability",
"refsource": "BUGTRAQ",
"url": "http://archives.neohapsis.com/archives/bugtraq/2014-10/0146.html"
},
{
"name": "http://packetstormsecurity.com/files/128842/EMC-Avamar-Weak-Password-Storage.html",
"refsource": "MISC",
"url": "http://packetstormsecurity.com/files/128842/EMC-Avamar-Weak-Password-Storage.html"
}
]
}
}