cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and gain access to the Management Console via an empty hash and empty encrypted password string, related to "stored decrypted user logon information."
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/24641 | vdb entry |
http://www.trendmicro.com/ftp/documentation/readme/osce_80_win_en_securitypatch_b1042_readme.txt | patch |
http://www.securityfocus.com/bid/24935 | vdb entry |
http://osvdb.org/36628 | vdb entry |
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=558 | third party advisory |
http://www.vupen.com/english/advisories/2007/2330 | vdb entry |
http://secunia.com/advisories/25778 | third party advisory patch vendor advisory |
http://www.securitytracker.com/id?1018320 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35052 | vdb entry |