René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

103 lines
3.1 KiB
JSON

{
"id": "CVE-2008-2747",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-06-18T19:41:00.000",
"lastModified": "2018-10-11T20:42:52.087",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\\SOFTWARE\\Vitalwerks\\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values."
},
{
"lang": "es",
"value": "No-IP Dynamic Update Client (DUC) 2.2.1 sobreWindows usa permisos d\u00e9biles para la clave de registro HKLM\\SOFTWARE\\Vitalwerks\\DUC, lo que permite a usuarios locales obtener contrase\u00f1as ofuscadas y otra informaci\u00f3n sensible leyendo los valores de registro (1) TrayPassword, (2) Username, (3) Password y (4) Hosts"
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 2.1
},
"baseSeverity": "LOW",
"exploitabilityScore": 3.9,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:no-ip:dynamic_update_client:2.2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "82ADAF61-8C0C-4231-BD1F-4BB54B786B38"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/3952",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/493367/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/29758",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43298",
"source": "cve@mitre.org"
}
]
}