CVE-2007-3455

critical

Description

cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and gain access to the Management Console via an empty hash and empty encrypted password string, related to "stored decrypted user logon information."

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/35052

http://www.vupen.com/english/advisories/2007/2330

http://www.trendmicro.com/ftp/documentation/readme/osce_80_win_en_securitypatch_b1042_readme.txt

http://www.securitytracker.com/id?1018320

http://www.securityfocus.com/bid/24935

http://www.securityfocus.com/bid/24641

http://secunia.com/advisories/25778

http://osvdb.org/36628

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=558

Details

Source: Mitre, NVD

Published: 2007-06-27

Updated: 2017-07-29

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical