First published: Fri Dec 31 2004(Updated: )
NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nessus Nessuswx | =1.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2723 is classified as a high severity vulnerability due to the exposure of sensitive account passwords.
To fix CVE-2004-2723, it's recommended to upgrade to a version of NessusWX that does not store passwords in plaintext.
The risks of CVE-2004-2723 include local users gaining unauthorized access to account passwords, potentially leading to further security breaches.
The only affected software noted for CVE-2004-2723 is NessusWX version 1.4.4.
CVE-2004-2723 cannot be exploited remotely, as it requires local access to the system to retrieve the plaintext passwords.