SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-1198

Comvigo IM Lock 2006 uses a simple substitution cipher to encrypt a password stored in the msnvs\prc registry value, for which all users have Read permission, which allows local users to bypass the product's blocking functionality by decrypting the…

LOW 3.7EPSS 0.30%

Does this matter?

Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.

Description

Comvigo IM Lock 2006 uses a simple substitution cipher to encrypt a password stored in the msnvs\prc registry value, for which all users have Read permission, which allows local users to bypass the product's blocking functionality by decrypting the password.

CVSS 2.0
3.7 LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
EPSS
0.30% probability · 22th percentile
CISA KEV
Not listed
Affected
comvigo/im lock
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.