Vulnerability Name: | CVE-2000-1173 (CCN-5578) | ||||||||
Assigned: | 2000-11-22 | ||||||||
Published: | 2000-11-22 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: BUGTRAQ Type: Exploit, Vendor Advisory 20001122 CyberPatrol - poor credit card protection Source: CCN Type: BugTraq Mailing List, Wed Nov 22 2000 - 07:41:25 CST CyberPatrol - poor credit card protection Source: MITRE Type: CNA CVE-2000-1173 Source: CCN Type: OSVDB ID: 11344 Microsys CyberPatrol Weak Encryption Credit Card Disclosure Source: BID Type: Exploit, Vendor Advisory 1977 Source: CCN Type: BID-1977 Microsys CyberPatrol Insecure Registration Vulnerability Source: XF Type: UNKNOWN cyberpatrol-insecure-data(5578) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |