Vulnerability Name:
CVE-2009-4304 (CCN-54989)
Assigned:
2009-12-02
Published:
2009-12-02
Updated:
2020-12-01
Summary:
Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.
CVSS v3 Severity:
5.3 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
Low
Availibility (A):
None
CVSS v2 Severity:
7.5 High
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
)
5.5 Medium
(Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
4.3 Medium
(CCN CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N
)
3.2 Low
(CCN Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
Partial
Availibility (A):
None
Vulnerability Type:
CWE-255
Vulnerability Consequences:
Other
References:
Source: MITRE
Type: CNA
CVE-2009-4304
Source: CONFIRM
Type: Patch
http://docs.moodle.org/en/Moodle_1.8.11_release_notes
Source: CCN
Type: Moodle Web site
Moodle 1.9.7 release notes
Source: CONFIRM
Type: Patch
http://docs.moodle.org/en/Moodle_1.9.7_release_notes
Source: CONFIRM
Type: Patch, Vendor Advisory
http://moodle.org/mod/forum/discuss.php?d=139111
Source: CCN
Type: SA37614
Moodle Multiple Vulnerabilities
Source: SECUNIA
Type: Vendor Advisory
37614
Source: CCN
Type: OSVDB ID: 61176
Moodle config.php Password Salt Brute Force Weakness
Source: BID
Type: Patch
37244
Source: CCN
Type: BID-37244
Moodle Multiple Vulnerabilities
Source: VUPEN
Type: Patch, Vendor Advisory
ADV-2009-3455
Source: XF
Type: UNKNOWN
moodle-config-weak-security(54989)
Source: FEDORA
Type: UNKNOWN
FEDORA-2009-13040
Source: FEDORA
Type: UNKNOWN
FEDORA-2009-13065
Source: FEDORA
Type: UNKNOWN
FEDORA-2009-13080
Source: SUSE
Type: SUSE-SR:2010:004
SUSE Security Summary Report
Vulnerable Configuration:
Configuration 1
:
cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.10:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.7:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.9:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.3:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.5:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.8:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.4:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.6:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.0:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.0:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.3:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.7:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.4:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.8:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.6:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.10:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.8.9:*:*:*:*:*:*:*
OR
cpe:/a:moodle:moodle:1.9.5:*:*:*:*:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.opensuse.security:def:20094304
V
CVE-2009-4304
2015-11-16
oval:com.ubuntu.precise:def:20094304000
V
CVE-2009-4304 on Ubuntu 12.04 LTS (precise) - medium.
2009-12-15
BACK
moodle
moodle 1.8.1
moodle
moodle 1.8.2
moodle
moodle 1.8.3
moodle
moodle 1.8.4
moodle
moodle 1.8.10
moodle
moodle 1.9.1
moodle
moodle 1.9.2
moodle
moodle 1.8.7
moodle
moodle 1.8.9
moodle
moodle 1.9.3
moodle
moodle 1.9.5
moodle
moodle 1.8.5
moodle
moodle 1.8.8
moodle
moodle 1.9.4
moodle
moodle 1.9.6
moodle
moodle 1.8.3
moodle
moodle 1.8.4
moodle
moodle 1.8.2
moodle
moodle 1.8.5
moodle
moodle 1.9.2
moodle
moodle 1.9.1
moodle
moodle 1.9
moodle
moodle 1.8.1
moodle
moodle 1.8
moodle
moodle 1.9.3
moodle
moodle 1.8.7
moodle
moodle 1.9.4
moodle
moodle 1.8.8
moodle
moodle 1.9.6
moodle
moodle 1.8.10
moodle
moodle 1.8.9
moodle
moodle 1.9.5