Vulnerability Description
Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers to bypass authentication and obtain access to backup files by leveraging a collision.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Retrospect | Retrospect | 10.0.2 |
| Retrospect | Retrospect Client | 10.0.2 |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/101500Third Party AdvisoryUS Government Resource
- http://www.retrospect.com/support/kb/cve_2015_2864PatchVendor Advisory
- http://www.securityfocus.com/bid/75201
- http://www.securitytracker.com/id/1033948
- https://www.youtube.com/watch?v=MB8AL5u7JCAExploit
- http://www.kb.cert.org/vuls/id/101500Third Party AdvisoryUS Government Resource
- http://www.retrospect.com/support/kb/cve_2015_2864PatchVendor Advisory
- http://www.securityfocus.com/bid/75201
- http://www.securitytracker.com/id/1033948
- https://www.youtube.com/watch?v=MB8AL5u7JCAExploit
FAQ
What is CVE-2015-2864?
CVE-2015-2864 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers...
How severe is CVE-2015-2864?
CVE-2015-2864 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2864?
Check the references section above for vendor advisories and patch information. Affected products include: Retrospect Retrospect, Retrospect Retrospect Client.