CVE-2004-2555
Last modified
CVE-2004-2555 is a vulnerability of currently unknown severity. Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the Control password to the Administrator password, which allows local users to calculate the Administrator password if they know the Control password and password recovery key.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the Control password to the Administrator password, which allows local users to calculate the Administrator password if they know the Control password and password recovery key.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Smartstuff | Foolproof Security | 3.9 |
| Smartstuff | Foolproof Security | 3.9.4 |
| Smartstuff | Foolproof Security | 3.9.7 |
References
- http://www.osvdb.org/6735Exploit
- http://www.osvdb.org/6735Exploit
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2555?
How severe is CVE-2004-2555?
How do I fix CVE-2004-2555?
Are you affected by CVE-2004-2555?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
