The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "SuperSecretPassword" as the hardcoded password, which allows local users to obtain the private key.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://osvdb.org/99518 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2013-11/0029.html | mailing list |
http://www.securityfocus.com/bid/63566 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/88606 | vdb entry |