VulnerabilityModified
CVE-2002-0343
Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords.
MEDIUM 4.6EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Affected
- hotline communications/hotline connect
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101495128121299&w=2
- http://www.iss.net/security_center/static/8327.phpVendor Advisory
- http://www.securityfocus.com/bid/4210Exploit, Vendor Advisory
- http://marc.info/?l=bugtraq&m=101495128121299&w=2
- http://www.iss.net/security_center/static/8327.phpVendor Advisory
- http://www.securityfocus.com/bid/4210Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.