CVE-2024-25102 Vulnerability Details

  /     /     /  

CVE-2024-25102 Metadata Quick Info

CVE Published: 06/03/2024 | CVE Updated: 23/09/2024 | CVE Year: 2024
Source: CERT-In | Vendor: CDAC | Product: AppSamvid Software
Status : PUBLISHED

CVE-2024-25102 Description

This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local administrative privileges could exploit this to obtain the password of AppSamvid on the targeted system. Successful exploitation of this vulnerability could allow the attacker to take complete control of the application on the targeted system.

Metrics

CVSS Version: 3.1 | Base Score: 7.8 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-326
CWE Name: CWE-326: Inadequate Encryption Strength
Source: CDAC

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-20
CAPEC Description: CAPEC-20: Encryption Brute Forcing


Source: NVD (National Vulnerability Database).