CVE-2014-9577

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
08/01/2015
Last modified:
12/04/2025

Description

VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain usernames and password hashes by logging in to TCP port 51410 and reading the response.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vdgsecurity:vdg_sense:2.3.13:*:*:*:*:*:*:*