CVE-2011-4432
 
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach.
www/include/configuration/nconfigObject/contact/DB-Func.php en Merethis Centreon antes de v2.3.2 no emplea "salt" durante el calculo del hash de una contraseña, lo que hace más sencillo para atacantes dependientes del contexto determinar las contraseñas en texto planto a través de una aproximación de tablas "rainbow".
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2011-11-09 CVE Reserved
- 2011-11-10 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/8530 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.trustwave.com/spiderlabs/advisories/TWSL2011-017.txt | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | <= 2.3.1 Search vendor "Merethis" for product "Centreon" and version " <= 2.3.1" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 1.4 Search vendor "Merethis" for product "Centreon" and version "1.4" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 1.4.1 Search vendor "Merethis" for product "Centreon" and version "1.4.1" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 1.4.2 Search vendor "Merethis" for product "Centreon" and version "1.4.2" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 1.4.2.1 Search vendor "Merethis" for product "Centreon" and version "1.4.2.1" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 1.4.2.2 Search vendor "Merethis" for product "Centreon" and version "1.4.2.2" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 1.4.2.3 Search vendor "Merethis" for product "Centreon" and version "1.4.2.3" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 1.4.2.4 Search vendor "Merethis" for product "Centreon" and version "1.4.2.4" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 1.4.2.5 Search vendor "Merethis" for product "Centreon" and version "1.4.2.5" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 1.4.2.6 Search vendor "Merethis" for product "Centreon" and version "1.4.2.6" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 1.4.2.7 Search vendor "Merethis" for product "Centreon" and version "1.4.2.7" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0 Search vendor "Merethis" for product "Centreon" and version "2.0" | b2 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0 Search vendor "Merethis" for product "Centreon" and version "2.0" | b3 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0 Search vendor "Merethis" for product "Centreon" and version "2.0" | b4 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0 Search vendor "Merethis" for product "Centreon" and version "2.0" | b5 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0 Search vendor "Merethis" for product "Centreon" and version "2.0" | b6 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0 Search vendor "Merethis" for product "Centreon" and version "2.0" | rc1 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0 Search vendor "Merethis" for product "Centreon" and version "2.0" | rc2 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0 Search vendor "Merethis" for product "Centreon" and version "2.0" | rc3 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0 Search vendor "Merethis" for product "Centreon" and version "2.0" | rc4 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0 Search vendor "Merethis" for product "Centreon" and version "2.0" | rc5 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0.1 Search vendor "Merethis" for product "Centreon" and version "2.0.1" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.0.2 Search vendor "Merethis" for product "Centreon" and version "2.0.2" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.0 Search vendor "Merethis" for product "Centreon" and version "2.1.0" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.1 Search vendor "Merethis" for product "Centreon" and version "2.1.1" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.2 Search vendor "Merethis" for product "Centreon" and version "2.1.2" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.3 Search vendor "Merethis" for product "Centreon" and version "2.1.3" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.4 Search vendor "Merethis" for product "Centreon" and version "2.1.4" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.5 Search vendor "Merethis" for product "Centreon" and version "2.1.5" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.6 Search vendor "Merethis" for product "Centreon" and version "2.1.6" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.7 Search vendor "Merethis" for product "Centreon" and version "2.1.7" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.8 Search vendor "Merethis" for product "Centreon" and version "2.1.8" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.9 Search vendor "Merethis" for product "Centreon" and version "2.1.9" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.10 Search vendor "Merethis" for product "Centreon" and version "2.1.10" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.11 Search vendor "Merethis" for product "Centreon" and version "2.1.11" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.12 Search vendor "Merethis" for product "Centreon" and version "2.1.12" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.1.13 Search vendor "Merethis" for product "Centreon" and version "2.1.13" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.2 Search vendor "Merethis" for product "Centreon" and version "2.2" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.2 Search vendor "Merethis" for product "Centreon" and version "2.2" | b1 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.2 Search vendor "Merethis" for product "Centreon" and version "2.2" | rc1 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.2 Search vendor "Merethis" for product "Centreon" and version "2.2" | rc2 |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.2.1 Search vendor "Merethis" for product "Centreon" and version "2.2.1" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.2.2 Search vendor "Merethis" for product "Centreon" and version "2.2.2" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.3.0 Search vendor "Merethis" for product "Centreon" and version "2.3.0" | - |
Affected
| ||||||
Merethis Search vendor "Merethis" | Centreon Search vendor "Merethis" for product "Centreon" | 2.3.0 Search vendor "Merethis" for product "Centreon" and version "2.3.0" | rc3 |
Affected
|