CRITICAL
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6
Published Mar 19, 2019
9.8
CRITICALCVSS 3.0
EPSS 1.09%
Description
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Passwords are stored using reversible encryption rather than as a hash value, and the used Vigenere algorithm is badly outdated. Moreover, the encryption key is static and too short. Due to this, the passwords stored by the application can be easily decrypted.
Affected products
Remediation
No remediation recorded yet.
References (3)
- http://packetstormsecurity.com/files/151118/PORTIER-4.4.4.2-4.4.4.6-Cryptographic-Issues.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://seclists.org/bugtraq/2019/Jan/8 mailing-listx_refsource_BUGTRAQExploitMailing ListThird Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-011.txt x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/151118/PORTIER-4.4.4.2-4.4.4.6-Cryptographic-Issues.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://seclists.org/bugtraq/2019/Jan/8 | mailing-listx_refsource_BUGTRAQExploitMailing ListThird Party Advisory | |
| https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-011.txt | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 19, 2019
Updated Aug 4, 2024
Reserved Jan 8, 2019
Link CVE-2019-5723
CISA Vulnrichment
Updated n/a