Lucene search

K
vulnrichmentSEC-VLabVULNRICHMENT:CVE-2024-36497
HistoryJun 24, 2024 - 9:06 a.m.

CVE-2024-36497 Unhashed Storage of Password

2024-06-2409:06:03
CWE-312
SEC-VLab
github.com
cve-2024-36497
password
cleartext
winselect

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%

The decrypted configuration file contains the password in cleartext
which is used to configure WINSelect. It can be used to remove the
existing restrictions and disable WINSelect entirely.

CNA Affected

[
  {
    "vendor": "Faronics",
    "product": "WINSelect (Standard + Enterprise)",
    "versions": [
      {
        "status": "unaffected",
        "version": "8.30.xx.903",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "affected"
  }
]

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%

Related for VULNRICHMENT:CVE-2024-36497