VulnerabilityModified
CVE-2002-2384
hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service.
LOW 3.6EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service.
- CVSS 2.0
- 3.6 LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- hotfoon corporation/hotfoon
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-11/0115.htmlExploit
- http://www.iss.net/security_center/static/10591.php
- http://www.securityfocus.com/bid/6155
- http://archives.neohapsis.com/archives/bugtraq/2002-11/0115.htmlExploit
- http://www.iss.net/security_center/static/10591.php
- http://www.securityfocus.com/bid/6155
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.