5.9
CVSSv3

CVE-2013-1351

Published: 30/01/2020 Updated: 10/02/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Verax NMS before 2.10 allows authentication via the encrypted password without knowing the cleartext password.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

veraxsystems network management system

Exploits

In versions prior to 210 of VeraxNMS, the server-side component eadministratorconsole-core-152jar, contains a method named decryptPassword() This method provides the functionality to decrypt a user's password using an implementation of RSA Within comveraxsystemseadministratorconsoleremoteserviceimpl, it has been discovered that decryptP ...
The primary client-side UI component of Verax NMS is a flash component named clientMainswf In addition to the Flash UI, Verax NMS uses AMF remoting for client/server communications As part of the login process, when a user logs in to the application, two parameters (username and password) are passed to the authenticateUser operation, which is pa ...