Demarc PureSecure Plaintext Password Vulnerability
BID:7650
Info
Demarc PureSecure Plaintext Password Vulnerability
| Bugtraq ID: | 7650 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 21 2003 12:00AM |
| Updated: | May 21 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Ryan Purita" <[email protected]>. |
| Vulnerable: |
Demarc PureSecure 1.0.6 |
| Not Vulnerable: | |
Discussion
Demarc PureSecure Plaintext Password Vulnerability
A problem with the Demarc PureSecure software could make unauthorized access to user credentials possible.
It has been reported that a problem exists in the method used in the storage of passwords by Demarc PureSecure. This could lead to users gaining unauthorized access to passwords, and potentially unauthorized access to the central/remote logging server.
It should be noted that although this vulnerability has been reported to affect Demarc PureSecure version 1.0.6 previous versions might also be affected.
A problem with the Demarc PureSecure software could make unauthorized access to user credentials possible.
It has been reported that a problem exists in the method used in the storage of passwords by Demarc PureSecure. This could lead to users gaining unauthorized access to passwords, and potentially unauthorized access to the central/remote logging server.
It should be noted that although this vulnerability has been reported to affect Demarc PureSecure version 1.0.6 previous versions might also be affected.
Exploit / POC
Demarc PureSecure Plaintext Password Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Demarc PureSecure Plaintext Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Demarc PureSecure Plaintext Password Vulnerability
References:
References:
- Demarc Homepage (Demarc)
- Demarc Puresecure v1.6 - Plaintext password issue - ("Ryan Purita"
)