Attacker Value
Moderate
(1 user assessed)
Exploitability
Very High
(1 user assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

Cerberus Helpdesk Workers File User Credentials Disclosure

Last updated March 25, 2020
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Cerberus Helpdesk on Version 4.2.3 Stable (Build 925) and 5.4.4 and potentially below, contain an unsecured file which contains configuration details including all user’s usernames and password hashes.

Add Assessment

1
Ratings
  • Attacker Value
    Medium
  • Exploitability
    Very High
Technical Analysis

Found this software in an enterprise environment. The /storage/tmp/devblocks_cache---ch_workersand /storage/tmp/zend_cache---ch_workersfiles contain lots of data, however the only things of value are a list of usernames and password hashes. When found in an enterprise, this gave us over 200 MD5 hashes, which was a huge win. Never seen the software before or after though.

General Information

References

Additional Info

Technical Analysis