First published: Tue Feb 21 2017(Updated: )
The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users to discover credentials by leveraging administrative access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dell VCE Vision Intelligent Operations | <=2.6.4 | |
<=2.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4056 has been assigned a medium severity rating due to improper implementation of cryptography.
To fix CVE-2015-4056, upgrade to VCE Vision Intelligent Operations version 2.6.5 or later.
CVE-2015-4056 affects all versions of VCE Vision Intelligent Operations prior to version 2.6.5.
CVE-2015-4056 is a cryptographic vulnerability that allows local users to potentially discover credentials.
CVE-2015-4056 requires local administrative access for exploitation, so it cannot be exploited remotely.