CVE-2008-2747
No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2)…
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- no-ip/dynamic update client
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/30714Vendor Advisory
- http://securityreason.com/securityalert/3952
- http://www.securityfocus.com/archive/1/493367/100/0/threaded
- http://www.securityfocus.com/bid/29758
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43298
- http://secunia.com/advisories/30714Vendor Advisory
- http://securityreason.com/securityalert/3952
- http://www.securityfocus.com/archive/1/493367/100/0/threaded
- http://www.securityfocus.com/bid/29758
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43298
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.