VulnerabilityModified
CVE-2001-0415
REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.
MEDIUM 4.6EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Affected
- redi/rediplus
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-03/0275.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/2495Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6276
- http://archives.neohapsis.com/archives/bugtraq/2001-03/0275.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/2495Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6276
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.