VulnerabilityModified
CVE-2007-3200
NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the admin username and password by reading this file.
MEDIUM 4.9EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the admin username and password by reading this file.
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Affected
- novell/modular authentication service
- Source
- cve@mitre.org
References
- http://osvdb.org/35943
- http://secunia.com/advisories/25592Vendor Advisory
- http://securitytracker.com/id?1018215
- http://www.securityfocus.com/bid/24405
- http://www.vupen.com/english/advisories/2007/2118
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34806
- https://secure-support.novell.com/KanisaPlatform/Publishing/249/3260550_f.SAL_Public.html
- http://osvdb.org/35943
- http://secunia.com/advisories/25592Vendor Advisory
- http://securitytracker.com/id?1018215
- http://www.securityfocus.com/bid/24405
- http://www.vupen.com/english/advisories/2007/2118
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34806
- https://secure-support.novell.com/KanisaPlatform/Publishing/249/3260550_f.SAL_Public.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.