vendor:
ZeroPort
by:
Brian Carrier
5.5
CVSS
MEDIUM
Weak Encryption
327
CWE
Product Name: ZeroPort
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:netzero:zeropoint
Platforms Tested: Windows
Unknown
Netzero Weak Encryption Vulnerability
Netzero, a free internet service provider, stores the username and password locally in a text file called id.dat. The encryption used for storing the credentials is weak and can be easily decrypted. The exploit allows malicious users to decrypt the username and password using a simple substitution cipher.
Mitigation:
Netzero should use stronger encryption algorithms to protect the stored credentials. It is recommended to update to a newer version of the application that addresses this vulnerability.