LOW · 2.1

CVE-2001-1550

CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impers...

Vulnerability Description

CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CentraAspAll versions
CentraCentraone5.2
CentraSmart Connectcen5.2-03

References

FAQ

What is CVE-2001-1550?

CVE-2001-1550 is a vulnerability with a CVSS score of 2.1 (LOW). CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impers...

How severe is CVE-2001-1550?

CVE-2001-1550 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2001-1550?

Check the references section above for vendor advisories and patch information. Affected products include: Centra Asp, Centra Centraone, Centra Smart Connect.