BindView NetInventory Password...

- AV AC AU C I A
发布: 2002-01-24
修订: 2025-04-13

NETinventory is a commercial system inventory solution distributed and maintained by BindView. It is available for Microsoft Windows and MSDOS Operating Systems. A problem with the program could make it possible for a local user to gain access to sensitive information. The problem is in the creation of the HOSTCFG._NI file. A system monitored by NETinventory typically stores credentials on the local file system. These credentials are stored in the HOSTCFG._NI file, and are usually protected. The credentials stored in HOSTCFG._NI include passwords. If the file is deleted and a new audit is initiated, the data stored in HOSTCFG._NI will be kept temporarily in the file 'HOSTCFG.INI' in plaintext. This may result in a disclosure of sensitive information to an attacker. The validity of this vulnerability has not been confirmed with BindView.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息