CVE-2005-1411 describes a local privilege escalation vulnerability in Cybration ICUII 7.0. The software stores user passwords in plaintext within the world-readable icuii.ini file. This allows any local user with access to the system to easily retrieve these credentials. The vulnerability has a CVSS score of 4.6, indicating a low attack complexity and requiring local access, but potentially leading to confidentiality, integrity, and availability impacts. While not on CISA's KEV catalog and lacking significant community discussion or media coverage, a public exploit (EDB-965) exists, demonstrating its exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:a:cybration:icuii:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.