|
Meridian Prolog Manager Password Brute Force Weakness
|
|
Secunia Advisory:
|
SA28065
|
|
|
Release Date:
|
2007-12-18
|
|
Popularity:
|
3,583 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Brute force Exposure of sensitive information
|
|
Where:
|
From local network
|
|
Solution Status:
|
Unpatched
|
|
| Software: | Meridian Prolog Manager 2007 Meridian Prolog Manager 7.x
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: A weakness has been reported in Meridian Prolog Manager, which can be exploited by malicious people to brute force user passwords.
The weakness is caused due to the server transmitting an encrypted dataset of all usernames and passwords to a client during login, using a weak encryption. This can be exploited to disclose usernames and passwords on the network via brute force attacks.
The complexity of the brute force attacks reportedly depends on which encryption setting was chosen ("No Encryption", "Standard Encryption", "Enhanced Encryption").
The weakness is reported in Prolog Manager versions 2007 and 7.5. Other versions may also be affected.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|