Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8x8-9hp6-3ppj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.3

Описание

iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read an encrypted version of the system's Personal Key in world-readable %PROGRAMDATA% log files. The encryption is done using a hard-coded static key and is therefore reversible by an attacker.

iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read an encrypted version of the system's Personal Key in world-readable %PROGRAMDATA% log files. The encryption is done using a hard-coded static key and is therefore reversible by an attacker.

EPSS

Процентиль: 20%
0.00065
Низкий

3.3 Low

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 3.3
nvd
больше 4 лет назад

iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read an encrypted version of the system's Personal Key in world-readable %PROGRAMDATA% log files. The encryption is done using a hard-coded static key and is therefore reversible by an attacker.

EPSS

Процентиль: 20%
0.00065
Низкий

3.3 Low

CVSS3

Дефекты

CWE-327