CVE-2013-6805: Weak Encryption
Published May 19, 2014
·Updated
OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffing the network or (2) local users to discover credentials by reading a .eod8 file.
Affected Software
1 affected component
OpenText Exceed OnDemand=8.0
Event History
May 19, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6805?
CVE-2013-6805 has a moderate severity due to weak encryption making credentials easier to compromise.
2
How do I fix CVE-2013-6805?
To fix CVE-2013-6805, upgrade to a newer version of OpenText Exceed OnDemand that uses stronger encryption.
3
What are the potential impacts of CVE-2013-6805?
The potential impacts of CVE-2013-6805 include unauthorized access to sensitive credentials and possible data breaches.
4
Which versions are affected by CVE-2013-6805?
CVE-2013-6805 affects OpenText Exceed OnDemand version 8.0.
5
Who can exploit CVE-2013-6805?
Both remote attackers and local users can exploit CVE-2013-6805 to discover plaintext credentials.