Vulnerabilities > Vdgsecurity > VDG Sense > 2.3.13

DATE CVE VULNERABILITY TITLE RISK
2015-01-08 CVE-2014-9579 Information Exposure vulnerability in Vdgsecurity VDG Sense 2.3.13
VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive information by reading the plugin configuration files.
network
low complexity
vdgsecurity CWE-200
5.0
2015-01-08 CVE-2014-9578 Improper Authentication vulnerability in Vdgsecurity VDG Sense 2.3.13
VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain login access by leveraging knowledge of a password hash.
network
low complexity
vdgsecurity CWE-287
5.0
2015-01-08 CVE-2014-9577 Information Exposure vulnerability in Vdgsecurity VDG Sense 2.3.13
VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain usernames and password hashes by logging in to TCP port 51410 and reading the response.
network
low complexity
vdgsecurity CWE-200
4.0
2015-01-08 CVE-2014-9576 Information Exposure vulnerability in Vdgsecurity VDG Sense 2.3.13
VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2) postgres and (3) NTP Windows user accounts, which allows remote attackers to obtain access.
network
low complexity
vdgsecurity CWE-200
5.0
2015-01-08 CVE-2014-9575 Permissions, Privileges, and Access Controls vulnerability in Vdgsecurity VDG Sense 2.3.13/2.3.14
VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin settings, via an encoded : (colon) character in the Authorization HTTP header.
network
low complexity
vdgsecurity CWE-264
6.4
2015-01-02 CVE-2014-9452 Path Traversal vulnerability in Vdgsecurity VDG Sense 2.3.13
Directory traversal vulnerability in VDG Security SENSE (formerly DIVA) 2.3.13 allows remote attackers to read arbitrary files via a ..
network
low complexity
vdgsecurity CWE-22
5.0
2015-01-02 CVE-2014-9451 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Vdgsecurity VDG Sense 2.3.13
Multiple stack-based buffer overflows in the DIVA web service API (/webservice) in VDG Security SENSE (formerly DIVA) 2.3.13 allow remote attackers to execute arbitrary code via the (1) user or (2) password parameter in an AuthenticateUser request.
network
low complexity
vdgsecurity CWE-119
7.5