Vulnerability Description
Comvigo IM Lock 2006 uses a simple substitution cipher to encrypt a password stored in the msnvs\prc registry value, for which all users have Read permission, which allows local users to bypass the product's blocking functionality by decrypting the password.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Comvigo | Im Lock | home_2006 |
References
- http://secunia.com/advisories/19140Vendor Advisory
- http://www.securityfocus.com/archive/1/426935/100/0/threaded
- http://www.securityfocus.com/bid/16988
- http://www.vupen.com/english/advisories/2006/0866
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25219
- http://secunia.com/advisories/19140Vendor Advisory
- http://www.securityfocus.com/archive/1/426935/100/0/threaded
- http://www.securityfocus.com/bid/16988
- http://www.vupen.com/english/advisories/2006/0866
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25219
FAQ
What is CVE-2006-1198?
CVE-2006-1198 is a vulnerability with a CVSS score of 3.7 (LOW). Comvigo IM Lock 2006 uses a simple substitution cipher to encrypt a password stored in the msnvs\prc registry value, for which all users have Read permission, which allows local users to bypass the pr...
How severe is CVE-2006-1198?
CVE-2006-1198 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1198?
Check the references section above for vendor advisories and patch information. Affected products include: Comvigo Im Lock.