VulnerabilityModified
CVE-2004-1851
Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via brute force guessing.
HIGH 7.5EPSS 1.13%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via brute force guessing.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.13% probability · 64th percentile
- CISA KEV
- Not listed
- Affected
- dameware development/mini remote control server
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=108016344224973&w=2
- http://secunia.com/advisories/11205Patch, Vendor Advisory
- http://securitytracker.com/id?1009557Vendor Advisory
- http://www.osvdb.org/4547Vendor Advisory
- http://www.securityfocus.com/bid/9957Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15587
- http://marc.info/?l=bugtraq&m=108016344224973&w=2
- http://secunia.com/advisories/11205Patch, Vendor Advisory
- http://securitytracker.com/id?1009557Vendor Advisory
- http://www.osvdb.org/4547Vendor Advisory
- http://www.securityfocus.com/bid/9957Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15587
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.