Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f48w-cm88-rf29

Опубликовано: 06 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to gain access to user accounts and access sensitive data used by the user account via unspecified vectors.

We have already fixed the vulnerability in the following version: QVPN Windows 2.1.0.0518 and later

An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to gain access to user accounts and access sensitive data used by the user account via unspecified vectors.

We have already fixed the vulnerability in the following version: QVPN Windows 2.1.0.0518 and later

EPSS

Процентиль: 6%
0.00024
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.7
nvd
больше 2 лет назад

An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to gain access to user accounts and access sensitive data used by the user account via unspecified vectors. We have already fixed the vulnerability in the following version: QVPN Windows 2.1.0.0518 and later

CVSS3: 6.7
fstec
больше 2 лет назад

Уязвимость программного обеспечения для подключения к удаленным VPN-серверам QVPN Device Client для Windows, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 6%
0.00024
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-522