CVE Vulnerabilities

CVE-2018-9031

Insufficiently Protected Credentials

Published: Mar 29, 2018 | Modified: Oct 03, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an if(pwd == line in the HTML source code. This means, in effect, that authentication occurs only on the client side.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Sentry_vision Tnlsoftsolutions 3.0 (including) 3.0 (including)
Sentry_vision Tnlsoftsolutions 3.1 (including) 3.1 (including)
Sentry_vision Tnlsoftsolutions 3.2 (including) 3.2 (including)

Potential Mitigations

References