CVE-2005-4002

WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation.
References
Link Resource
http://www.kb.cert.org/vuls/id/388282 Patch Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/388282 Patch Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:esi_products:webeoc:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:03

Type Values Removed Values Added
References () http://www.kb.cert.org/vuls/id/388282 - Patch, Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/388282 - Patch, Third Party Advisory, US Government Resource

Information

Published : 2005-12-05 00:03

Updated : 2024-11-21 00:03


NVD link : CVE-2005-4002

Mitre link : CVE-2005-4002

CVE.ORG link : CVE-2005-4002


JSON object : View

Products Affected

esi_products

  • webeoc