Verax NMS contains a flaw in the authenticateUser operation that is due to the program storing hard coded private and public keys in clientMain.swf. This may allow a remote attacker to capture the encoded password and replay the password in order to bypass authentication.
Disclosure Timeline:
Vendor Informed Date :2013-01-10
Vendor Ack Date :2013-01-11
Vendor Solution Date :2013-02-20
Disclosure Date :2013-03-07
Exploit Publish Date :2013-03-07