Vulnerability Description
ReadyDesk 9.1 allows local users to determine cleartext SQL Server credentials by reading the SQL_Config.aspx file and decrypting data with a hardcoded key in the ReadyDesk.dll file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Readydesk | Readydesk | 9.1 |
References
- http://www.kb.cert.org/vuls/id/294272Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/92487
- http://www.kb.cert.org/vuls/id/294272Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/92487
FAQ
What is CVE-2016-5683?
CVE-2016-5683 is a vulnerability with a CVSS score of 7.8 (HIGH). ReadyDesk 9.1 allows local users to determine cleartext SQL Server credentials by reading the SQL_Config.aspx file and decrypting data with a hardcoded key in the ReadyDesk.dll file.
How severe is CVE-2016-5683?
CVE-2016-5683 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5683?
Check the references section above for vendor advisories and patch information. Affected products include: Readydesk Readydesk.