Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers to bypass authentication and obtain access to backup files by leveraging a collision.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/101500 | Third Party Advisory US Government Resource |
http://www.retrospect.com/support/kb/cve_2015_2864 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/75201 | |
http://www.securitytracker.com/id/1033948 | |
https://www.youtube.com/watch?v=MB8AL5u7JCA | Exploit |
http://www.kb.cert.org/vuls/id/101500 | Third Party Advisory US Government Resource |
http://www.retrospect.com/support/kb/cve_2015_2864 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/75201 | |
http://www.securitytracker.com/id/1033948 | |
https://www.youtube.com/watch?v=MB8AL5u7JCA | Exploit |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:28
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.kb.cert.org/vuls/id/101500 - Third Party Advisory, US Government Resource | |
References | () http://www.retrospect.com/support/kb/cve_2015_2864 - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/75201 - | |
References | () http://www.securitytracker.com/id/1033948 - | |
References | () https://www.youtube.com/watch?v=MB8AL5u7JCA - Exploit |
Information
Published : 2015-09-21 10:59
Updated : 2024-11-21 02:28
NVD link : CVE-2015-2864
Mitre link : CVE-2015-2864
CVE.ORG link : CVE-2015-2864
JSON object : View
Products Affected
retrospect
- retrospect_client
- retrospect
CWE
CWE-255
Credentials Management Errors