Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8mv-f94r-2px4

Опубликовано: 14 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileges to extract plain text passwords easily.

This issue affects BASEC: from 14 Dec 2021.

Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileges to extract plain text passwords easily.

This issue affects BASEC: from 14 Dec 2021.

EPSS

Процентиль: 13%
0.00043
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-522

Связанные уязвимости

nvd
10 месяцев назад

Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileges to extract plain text passwords easily. This issue affects BASEC: from 14 Dec 2021.

EPSS

Процентиль: 13%
0.00043
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-522