| Vulnerability Name: | CVE-2011-3013 (CCN-69168) | ||||||||
| Assigned: | 2011-08-05 | ||||||||
| Published: | 2011-08-05 | ||||||||
| Updated: | 2017-08-29 | ||||||||
| Summary: | WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for remote attackers to obtain access via a brute-force attack. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-310 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2011-3013 Source: CCN Type: Novell Document ID: 7009056 Weak SSL Ciphers supported with WebAdmin Source: CONFIRM Type: Vendor Advisory http://www.novell.com/support/viewContent.do?externalId=7009056 Source: CCN Type: OSVDB ID: 74523 Novell Data Synchronizer Mobility Pack WebAdmin Weak SSL Cipher Support Brute Force Weakness Source: XF Type: UNKNOWN novell-data-webadmin-unauth-access(69168) Source: XF Type: UNKNOWN novell-data-webadmin-unauth-access(69168) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||