CVE-2015-2864
Summary
| CVE | CVE-2015-2864 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-09-21 10:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers to bypass authentication and obtain access to backup files by leveraging a collision. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Retrospect | Retrospect | 10.0.2 | All | All | All |
| Application | Retrospect | Retrospect | 12.0.2 | All | All | All |
| Application | Retrospect | Retrospect Client | 10.0.2 | All | All | All |
| Application | Retrospect | Retrospect Client | 10.0.2 | All | All | All |
| Application | Retrospect | Retrospect Client | 12.0.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Retrospect Backup Client CVE-2015-2864 Weak Password Security Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Retrospect Password Hashing Error Lets Remote Users Access Files on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Vulnerability Note VU#101500 - Retrospect Backup Client uses weak password hashing | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Retrospect: Knowledge Base > CERT Vulnerability CVE-2015-2864 | af854a3a-2127-422b-91ae-364da2661108 | www.retrospect.com | Patch, Vendor Advisory |
| HIP14-Fuzzing reversing and maths - YouTube | af854a3a-2127-422b-91ae-364da2661108 | www.youtube.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.