DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
http://www.dameware.com/support/security/bulletin.asp?ID=SB3 | product vendor advisory |
http://marc.info/?l=bugtraq&m=108016344224973&w=2 | third party advisory mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15586 | vdb entry third party advisory |
http://securitytracker.com/id?1009557 | vendor advisory vdb entry third party advisory broken link |
http://www.osvdb.org/4547 | vdb entry broken link vendor advisory |
http://secunia.com/advisories/11205 | broken link third party advisory patch vendor advisory |
http://www.securityfocus.com/bid/9959 | patch vendor advisory vdb entry third party advisory broken link |