Back to Database
Status published
Medium
CVE-2014-9578
VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a...
Vulnerability Description
VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain login access by leveraging knowledge of a password hash.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9578
Credits & Attribution
No credits recorded in the NVD database.
References
- http://seclists.org/fulldisclosure/2014/Dec/76
- http://packetstormsecurity.com/files/129656/VDG-Security-SENSE-2.3.13-File-Disclosure-Bypass-Buffer-Overflow.html
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20141218-0_VDG_Security_SENSE_Multiple_critical_vulnerabilities_v10.txt
More from vdgsecurity
View All →CVE-2014-9579
VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in...
Medium
5
CVE-2014-9577
VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database...
Medium
4
CVE-2014-9576
VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password...
Medium
5
CVE-2014-9575
VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers...
Medium
6.4
CVE-2014-9452
Directory traversal vulnerability in VDG Security SENSE (formerly DIVA) 2.3.13...
Medium
5
Affected Vendor
vdgsecurity
View all reports →Affected Software
vdg sense
Vulnerable Versions:
2.3.13
Timeline
Official Publish:
January 8th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.