MEDIUM · 5.0

CVE-2015-2864

Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers...

Vulnerability Description

Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers to bypass authentication and obtain access to backup files by leveraging a collision.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
RetrospectRetrospect10.0.2
RetrospectRetrospect Client10.0.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2864?

CVE-2015-2864 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers...

How severe is CVE-2015-2864?

CVE-2015-2864 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2864?

Check the references section above for vendor advisories and patch information. Affected products include: Retrospect Retrospect, Retrospect Retrospect Client.