Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3q48-cqgx-wj5v

Опубликовано: 10 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.7
CVSS3: 5.5

Описание

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files containing serialized JSON with passwords.

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files containing serialized JSON with passwords.

EPSS

Процентиль: 2%
0.00013
Низкий

6.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.5
nvd
5 месяцев назад

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files containing serialized JSON with passwords.

EPSS

Процентиль: 2%
0.00013
Низкий

6.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-532