Vulnerabilities > CVE-2002-2384 - Credentials Management vulnerability in Hotfoon Corporation Hotfoon 4.0

047910
CVSS 3.6 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
local
low complexity
hotfoon-corporation
CWE-255

Summary

hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service.

Vulnerable Configurations

Part Description Count
Application
Hotfoon_Corporation
1

Common Weakness Enumeration (CWE)