T
he Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 uses weak cryptography (XOR) when (1) transmitting passwords, which allows remote attackers to obtain sensitive information by sniffing the network; and (2) storing passwords in the configuration file, which allows local users to obtain sensitive information by reading this file.
References
| Link | Resource |
|---|---|
| http://osvdb.org/46979 | Broken Link |
| http://www.portcullis.co.uk/uplds/advisories/vapassword%20-%2006-042.txt | Broken Link Vendor Advisory |
| http://www.securityfocus.com/bid/25153 | Broken Link Third Party Advisory VDB Entry |
| http://osvdb.org/46979 | Broken Link |
| http://www.portcullis.co.uk/uplds/advisories/vapassword%20-%2006-042.txt | Broken Link Vendor Advisory |
| http://www.securityfocus.com/bid/25153 | Broken Link Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 00:34
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://osvdb.org/46979 - Broken Link | |
| References | () http://www.portcullis.co.uk/uplds/advisories/vapassword%20-%2006-042.txt - Broken Link, Vendor Advisory | |
| References | () http://www.securityfocus.com/bid/25153 - Broken Link, Third Party Advisory, VDB Entry |
Information
Published : 2007-08-03 20:17
Updated : 2025-04-09 00:30
NVD link : CVE-2007-4150
Mitre link : CVE-2007-4150
CVE.ORG link : CVE-2007-4150
JSON object : View
Products Affected
CWE
CWE-327
Use of a Broken or Risky Cryptographic Algorithm