Vulnerabilities > CVE-2005-0809 - Multiple vulnerability in Notify Technology Notifylink Enterpriseserver
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |