Vulnerability Name: | CVE-2009-4304 (CCN-54989) |
Assigned: | 2009-12-02 |
Published: | 2009-12-02 |
Updated: | 2020-12-01 |
Summary: | Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-255
|
Vulnerability Consequences: | Other |
References: | Source: MITRE Type: CNA CVE-2009-4304
Source: CONFIRM Type: Patch http://docs.moodle.org/en/Moodle_1.8.11_release_notes
Source: CCN Type: Moodle Web site Moodle 1.9.7 release notes
Source: CONFIRM Type: Patch http://docs.moodle.org/en/Moodle_1.9.7_release_notes
Source: CONFIRM Type: Patch, Vendor Advisory http://moodle.org/mod/forum/discuss.php?d=139111
Source: CCN Type: SA37614 Moodle Multiple Vulnerabilities
Source: SECUNIA Type: Vendor Advisory 37614
Source: CCN Type: OSVDB ID: 61176 Moodle config.php Password Salt Brute Force Weakness
Source: BID Type: Patch 37244
Source: CCN Type: BID-37244 Moodle Multiple Vulnerabilities
Source: VUPEN Type: Patch, Vendor Advisory ADV-2009-3455
Source: XF Type: UNKNOWN moodle-config-weak-security(54989)
Source: FEDORA Type: UNKNOWN FEDORA-2009-13040
Source: FEDORA Type: UNKNOWN FEDORA-2009-13065
Source: FEDORA Type: UNKNOWN FEDORA-2009-13080
Source: SUSE Type: SUSE-SR:2010:004 SUSE Security Summary Report
|
Vulnerable Configuration: | Configuration 1: cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.10:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.7:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.9:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.8:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.6:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.7:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.8:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.10:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.9:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.5:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |