CVE-2016-0321

Description

IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging access to the victim account and executing a PowerShell script.

Risk Information

Base Score
6.2
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.134

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 12.0.0Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.0Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.1Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.10Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.11Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.12Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.13Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.14Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.15Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.16Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.2Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.3Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.4Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.5Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.6Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.7Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.8Windows
Vulnerabilities CVE-2016-0321 are affected in IBM Personal Communications 6.0.9Windows
Vulnerabilities CVE-2014-3566,CVE-2016-0321 are affected in IBM Personal Communications 6.0.11Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234