CVE Vulnerabilities

CVE-2014-2581

Insufficiently Protected Credentials

Published: Jan 28, 2020 | Modified: Jan 30, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the Additional options line edit.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Smb4k Smb4k_project * 1.1.1 (excluding)
Smb4k Ubuntu artful *
Smb4k Ubuntu lucid *
Smb4k Ubuntu precise *
Smb4k Ubuntu quantal *
Smb4k Ubuntu saucy *
Smb4k Ubuntu trusty *
Smb4k Ubuntu upstream *
Smb4k Ubuntu utopic *
Smb4k Ubuntu vivid *
Smb4k Ubuntu wily *
Smb4k Ubuntu xenial *
Smb4k Ubuntu yakkety *
Smb4k Ubuntu zesty *

Potential Mitigations

References