Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sambar Server默认配置密码加密漏洞
Vulnerability Description
Sambar Server 5及其之前版本的默认配置会使用加密密码二进制程序编译的对称密钥,远程攻击者可以通过破解密钥或修改sambar程序副本来调用译码程序,从而破解所有用户的密码。
CVSS Information
N/A
Vulnerability Type
N/A