Cisco Mac OS VPN 5000 Client Password Disclosure Vulnerability
BID:5736
Info
Cisco Mac OS VPN 5000 Client Password Disclosure Vulnerability
| Bugtraq ID: | 5736 |
| Class: | Design Error |
| CVE: |
CVE-2002-1491 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 18 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | This issue was publicized in a Cisco Security Advisory. |
| Vulnerable: |
Cisco VPN 5000 Client for Mac OS 5.2.1 Cisco VPN 5000 Client for Mac OS 5.1.2 |
| Not Vulnerable: |
Cisco VPN 5000 Client for Mac OS 5.2.2 |
Discussion
Cisco Mac OS VPN 5000 Client Password Disclosure Vulnerability
The Cisco VPN 5000 Client on Mac OS saves configuration information for the default connection in the resource fork of the preferences file. Authentication credentials for the most recent login are included in the configuration. A tool such as ResEdit may be used to extract this information.
The Cisco VPN 5000 Client on Mac OS saves configuration information for the default connection in the resource fork of the preferences file. Authentication credentials for the most recent login are included in the configuration. A tool such as ResEdit may be used to extract this information.
References
Cisco Mac OS VPN 5000 Client Password Disclosure Vulnerability
References:
References: