Vulnerability Name: | CCN-13 | ||||||
Published: | 1996-05-01 | ||||||
Updated: | 1996-05-01 | ||||||
Summary: | Microsoft Network Monitor (NetMon) uses a weak encryption password scheme in the BHSUPP.DLL file that could allow an attacker to gain unauthorized access to the network monitor. If an attacker has access to the BHSUPP.DLL file, the attacker could decrypt the password to gain access to the network monitor and obtain sensitive information. | ||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:W/RC:UR)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: Phrack Magazine, Volume 7, Issue 48, Article 15 of 18 Windows NT Network Monitor Exploitation Source: CCN Type: BID-6788 Microsoft Windows Network Monitor Weak Password Encryption Vulnerability Source: XF Type: UNKNOWN nt-netmon(13) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |