First published: Thu Mar 24 2005(Updated: )
Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nortel Contivity | =5.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-0844 is considered to be medium as it allows local users to access sensitive information.
To fix CVE-2005-0844, users should upgrade to a newer version of the Nortel VPN client that does not store passwords in cleartext.
CVE-2005-0844 specifically affects Nortel VPN client version 5.01.
CVE-2005-0844 is a local information disclosure vulnerability.
Local users on systems running the affected version of the Nortel VPN client are at risk due to CVE-2005-0844.