LOW · 3.6

CVE-2002-2384

hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service.

Vulnerability Description

hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service.

CVSS Score

3.6

LOW

AV:L/AC:L/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Hotfoon CorporationHotfoon4.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2002-2384?

CVE-2002-2384 is a vulnerability with a CVSS score of 3.6 (LOW). hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service.

How severe is CVE-2002-2384?

CVE-2002-2384 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-2384?

Check the references section above for vendor advisories and patch information. Affected products include: Hotfoon Corporation Hotfoon.