vendor:
BrowseGate
by:
NetCplus
7.5
CVSS
HIGH
Weak Encryption
327
CWE
Product Name: BrowseGate
Affected Version From: All versions of BrowseGate
Affected Version To: All versions of BrowseGate
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
BrowseGate Password Decryption
A design error in BrowseGate allows an authenticated user to view other users' encrypted passwords. The encrypted password is stored in the 'brwgate.ini' configuration file and can be decrypted using a weak encryption scheme.
Mitigation:
Apply a patch or update to a version of BrowseGate that uses a stronger encryption scheme for storing passwords.