CVE-2015-2864 describes an improper password hash generation vulnerability in Retrospect and Retrospect Client software across Windows, OS X, and Linux platforms prior to specific versions. This flaw allows remote attackers to bypass authentication and access backup files by exploiting hash collisions. With a CVSS score of 5.0 (medium severity), this vulnerability is network-exploitable with low attack complexity, requiring no authentication, and primarily impacts confidentiality (data access). There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0.2CPE matchmatch criteria | cpe:2.3:a:retrospect:retrospect:10.0.2:*:*:*:*:windows:*:* | ||
12.0.2CPE matchmatch criteria | cpe:2.3:a:retrospect:retrospect:12.0.2:*:*:*:*:mac:*:* | ||
10.0.2CPE matchmatch criteria | cpe:2.3:a:retrospect:retrospect_client:10.0.2:*:*:*:*:linux:*:* | ||
10.0.2CPE matchmatch criteria | cpe:2.3:a:retrospect:retrospect_client:10.0.2:*:*:*:*:windows:*:* | ||
12.0.2CPE matchmatch criteria | cpe:2.3:a:retrospect:retrospect_client:12.0.2:*:*:*:*:mac:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.