CVE-2004-1902
Description
Citrix MetaFrame Password Manager 2.0 stores passwords unencrypted when no central credential store is configured, allowing local users to read them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Citrix MetaFrame Password Manager 2.0 stores passwords unencrypted when no central credential store is configured, allowing local users to read them.
Vulnerability
Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, fails to encrypt passwords entered immediately after executing the First Time User Wizard. The credentials are stored in the local store in plaintext instead of being encrypted with 3DES as expected. This affects installations on Windows 2000 and Windows XP where the administrator has not pointed the agent to a central store [1].
Exploitation
An attacker with local access to the system can read the unencrypted credentials from the local credential store. The store is protected by Windows file ACLs that restrict access to the user or Administrator, so the attacker must already have user-level or administrative rights on the machine. No network access or user interaction beyond the initial configuration is required [1].
Impact
Successful exploitation leads to disclosure of the passwords entered into the Password Manager, which may include credentials for applications, systems, and web sites. This compromises the confidentiality of the user's secondary logon credentials, potentially allowing the attacker to authenticate to other resources [1].
Mitigation
The vulnerability is mitigated by ensuring a central credential store is configured, which causes encryption to be applied. Citrix released a vendor advisory (link not directly provided in the reference) [1]. Administrators should either configure a central store or apply any available update from Citrix. No workaround is available other than proper configuration [1].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2cpe:2.3:a:citrix:metaframe_password_manager:2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:citrix:metaframe_password_manager:2.0:*:*:*:*:*:*:*
- (no CPE)range: = 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/11293nvdPatch
- support.citrix.com/kb/entry.jspanvdPatchVendor Advisory
- www.securityfocus.com/bid/10049nvdPatch
- marc.infonvd
- securitytracker.com/idnvd
- www.osvdb.org/4942nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/15737nvd
News mentions
0No linked articles in our index yet.