Conductor.exe in Intrinsic Swimage Encore before 5.0.1.21 contains a hardcoded password, which might allow local users to decrypt certain .bin files. NOTE: it is not clear whether this issue crosses privilege boundaries.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://secunia.com/advisories/31540 | third party advisory |
http://www.kb.cert.org/vuls/id/778427 | third party advisory us government resource |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44538 | vdb entry |
http://www.securityfocus.com/bid/30736 | vdb entry |