CVE-1999-0356

CVSS 2.0 Score 10.0 of 10 (high)

Details

Published Jan 25, 1999
Updated: Nov 20, 2024

Summary

CVE-1999-0356 is a vulnerability affecting ControlIT version 4.5 and earlier. The issue lies in the software's weak encryption method used to store usernames and passwords in an address book. An attacker who gains unauthorized access to the address book can easily retrieve sensitive user credentials, potentially leading to unauthorized access to the controlled systems. This vulnerability highlights the importance of implementing strong encryption and secure storage for sensitive information. Users are advised to upgrade to the latest version of ControlIT or take other protective measures to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share