|
|
|
Vulnerability Note VU#139139
Air Messenger LAN Server (AMLServer) stores usernames and passwords in plaintext
OverviewAir Messenger LAN Server (AMLServer) stores usernames and passwords in plaintext.
I. DescriptionAMLServer for windows is a paging gateway that allows users on a TCP/IP LAN to communicate with mobile devices such as phones and pagers. Access to AMLServer's services is protected by a user authentication system that stores usernames and passwords in a plaintext file.II. ImpactIf an attacker can view the AMLServer password file (through direct access or another vulnerability), they can login as any AMLServer user.III. SolutionApply a patch when one is available. The CERT/CC is currently unaware of a practical solution to this problem.
None.
Systems Affected
References
http://www.securityfocus.com/bid/2882
Credit
Thanks to SNS Research for discovering this vulnerability.
This document was written by Shawn Van Ittersum.
Other Information
| Date Public | 06/18/2001 |
| Date First Published | 10/25/2001 10:03:36 PM |
| Date Last Updated | 10/25/2001 |
| CERT Advisory | |
| CVE Name | |
| Metric | 0.07 |
| Document Revision | 9 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |