First published: Tue Mar 01 2005(Updated: )
lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GFI Languard Network Security Scanner | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0604 has a high severity rating due to the risk of exposing domain administrator credentials.
To mitigate CVE-2005-0604, update GFI Languard Network Security Scanner to a version that securely handles stored credentials.
CVE-2005-0604 affects GFI Languard Network Security Scanner version 5.0.
CVE-2005-0604 exposes usernames and passwords stored in memory in plaintext.
Local administrators can exploit CVE-2005-0604 to obtain sensitive credentials in the affected software.