Vulnerability Description
Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intego | Diskguard | 2.0 |
| Intego | Fileguard | 4.0 |
References
- http://www.iss.net/security_center/static/7018.phpVendor Advisory
- http://www.securemac.com/fileguard.php#disengage
- http://www.securityfocus.com/bid/3213ExploitVendor Advisory
- http://www.iss.net/security_center/static/7018.phpVendor Advisory
- http://www.securemac.com/fileguard.php#disengage
- http://www.securityfocus.com/bid/3213ExploitVendor Advisory
FAQ
What is CVE-2001-1165?
CVE-2001-1165 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool.
How severe is CVE-2001-1165?
CVE-2001-1165 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1165?
Check the references section above for vendor advisories and patch information. Affected products include: Intego Diskguard, Intego Fileguard.