VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain login access by leveraging knowledge of a password hash.
References
Configurations
History
No history.
Information
Published : 2015-01-08 15:59
Updated : 2024-02-04 18:35
NVD link : CVE-2014-9578
Mitre link : CVE-2014-9578
CVE.ORG link : CVE-2014-9578
JSON object : View
Products Affected
vdgsecurity
- vdg_sense
CWE
CWE-287
Improper Authentication