vendor:
Endpoint Protector
by:
Chris Campbell
7,5
CVSS
HIGH
Insecure Password Generation
259
CWE
Product Name: Endpoint Protector
Affected Version From: CoSoSys Endpoint Protector 4
Affected Version To: CoSoSys Endpoint Protector 4
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
CoSoSys Endpoint Protector Insecure Password Generation Vulnerability
CoSoSys Endpoint Protector is prone to an insecure password generation vulnerability. Successfully exploiting this issue may allow an attacker to guess generated passwords and gain access to affected appliances. CoSoSys Endpoint Protector 4 is vulnerable; other versions may also be affected.
Mitigation:
Vendor has released a patch to address this issue.