MEDIUM · 5.0

CVE-2011-4432

www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent att...

Vulnerability Description

www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MerethisCentreon<= 2.3.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-4432?

CVE-2011-4432 is a vulnerability with a CVSS score of 5.0 (MEDIUM). www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent att...

How severe is CVE-2011-4432?

CVE-2011-4432 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-4432?

Check the references section above for vendor advisories and patch information. Affected products include: Merethis Centreon.