VDB
CVE-2011-2082
CVE-2011-2082
PUBLISHED
CVSS 5 MEDIUM
The vulnerable-passwords script in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not update the password-hash algorithm for disabled user accounts, which makes it easier for context-dependent attackers to determine cleartext passwords, and possibly use these passwords after accounts are re-enabled, via a brute-force attack on the database. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0009.
EPSS 0.37% · 59.0th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
0.37%
59.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| bestpractical | rt | 3.0.12, 3.0.0, 3.0.1 |
| n/a | n/a | * |
Timeline
- Jun 4, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- [rt-announce] 20120522 RT 3.8.12 Released - Security Release mailing-list
- 49259 third-party-advisory
- [rt-announce] 20120522 RT 4.0.6 Released - Security Release mailing-list
- [rt-announce] 20120522 Security vulnerabilities in RT mailing-list
- 53660 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2011-2082 advisory