CVE-2001-1106 describes a critical vulnerability in Sambar Server versions 5 and earlier, where a hardcoded symmetric key is used for password encryption. This design flaw allows local attackers to decrypt all user passwords by either cracking the key or modifying the server's binary to access the decryption routine. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-exploitable flaw with low attack complexity and potential for partial compromise of confidentiality, integrity, and availability. While not listed on KEV or having Metasploit/Nuclei exploits, an ExploitDB entry exists, and community discussion is notably high for a CVE of its age, suggesting continued awareness despite its inactive Hot List status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1CPE matchmatch criteria | cpe:2.3:a:sambar:sambar_server:4.1:*:*:*:*:*:*:* | ||
4.2.1_productionCPE matchmatch criteria | cpe:2.3:a:sambar:sambar_server:4.2.1_production:*:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:sambar:sambar_server:4.3:*:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:a:sambar:sambar_server:4.4:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:sambar:sambar_server:5.0:beta1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.