| Solutionary ID: SERT-VDN-1004 |
| CVE ID: CVE-2011-3685 |
| Product: Tembria Server Monitor |
| Application Vendor: Tembria |
| Vendor URL: http://www.tembria.com/products/servermonitor/index.html |
| Date discovered: 1/22/2011 |
| Discovered by: Rob Kraus and Solutionary Engineering Research Team (SERT) |
| Vendor notification date: 1/25/2011 |
| Vendor response date: 1/25/2011 |
| Vendor acknowledgment date: 1/25/2011 |
Public disclosure date: 2/14/2011 Exploit Vectors: Local Tested on: Windows XP, SP3, with Tembria Server Monitor v6.0.4 - Build 2229 default installation. Affected software versions: Tembria Server Monitor v6.0.4 - Build 2229 default installation Impact: In cases where access to the previously mentioned files is obtained, an attacker can decrypt all username and password values and potentially reuse them for authentication to other systems within the network environment. Fixed in: Tembria Server Monitor v6.0.5 - Build 2252 Remediation guidelines: The vendor has created a fix to address the discovered issues. Upgrade to Tembria Server Monitor v6.0.5 - Build 2252 or later. |
- Trusted Managed Security Provider | Solutionary
- Research
- Vulnerability Disclosures
- Tembria Server Monitor Weak Cryptographic Password Storage Vulnerability

