VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-1902

CVE-2004-1902

Description

Citrix MetaFrame Password Manager 2.0 stores passwords unencrypted when no central credential store is configured, allowing local users to read them.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Citrix MetaFrame Password Manager 2.0 stores passwords unencrypted when no central credential store is configured, allowing local users to read them.

Vulnerability

Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, fails to encrypt passwords entered immediately after executing the First Time User Wizard. The credentials are stored in the local store in plaintext instead of being encrypted with 3DES as expected. This affects installations on Windows 2000 and Windows XP where the administrator has not pointed the agent to a central store [1].

Exploitation

An attacker with local access to the system can read the unencrypted credentials from the local credential store. The store is protected by Windows file ACLs that restrict access to the user or Administrator, so the attacker must already have user-level or administrative rights on the machine. No network access or user interaction beyond the initial configuration is required [1].

Impact

Successful exploitation leads to disclosure of the passwords entered into the Password Manager, which may include credentials for applications, systems, and web sites. This compromises the confidentiality of the user's secondary logon credentials, potentially allowing the attacker to authenticate to other resources [1].

Mitigation

The vulnerability is mitigated by ensuring a central credential store is configured, which causes encryption to be applied. Citrix released a vendor advisory (link not directly provided in the reference) [1]. Administrators should either configure a central store or apply any available update from Citrix. No workaround is available other than proper configuration [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:citrix:metaframe_password_manager:2.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:citrix:metaframe_password_manager:2.0:*:*:*:*:*:*:*
    • (no CPE)range: = 2.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.