CVE-2001-1165: Weak Encryption
Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1165?
CVE-2001-1165 is considered a high severity vulnerability due to weak encryption that allows local users to access sensitive information.
How do I fix CVE-2001-1165?
To fix CVE-2001-1165, upgrade to the latest version of Intego FileGuard that addresses this weak encryption flaw.
What software is affected by CVE-2001-1165?
CVE-2001-1165 affects Intego FileGuard version 4.0 and Intego DiskGuard version 2.0.
What type of attack does CVE-2001-1165 enable?
CVE-2001-1165 enables local users to gain unauthorized privileges by decrypting user information stored with weak encryption.
Is my system at risk if I use RTE to manage Intego FileGuard versions?
If you are using affected versions of Intego FileGuard, then your system is at risk from CVE-2001-1165 until an upgrade is applied.