Vulnerability Description
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/www/xms/xmsdb/default.db.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dialogic | Powermedia Xms | <= 3.5 |
Related Weaknesses (CWE)
References
- https://d3adend.org/blog/?p=1398ExploitThird Party Advisory
- https://d3adend.org/blog/?p=1398ExploitThird Party Advisory
FAQ
What is CVE-2018-11634?
CVE-2018-11634 is a vulnerability with a CVSS score of 7.8 (HIGH). Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/ww...
How severe is CVE-2018-11634?
CVE-2018-11634 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11634?
Check the references section above for vendor advisories and patch information. Affected products include: Dialogic Powermedia Xms.