Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rgh8-pfpq-pp5g

Опубликовано: 21 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable.

This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.

The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable.

This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.

EPSS

Процентиль: 1%
0.00009
Низкий

8.5 High

CVSS4

Дефекты

CWE-321

Связанные уязвимости

nvd
18 дней назад

The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable. This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.

EPSS

Процентиль: 1%
0.00009
Низкий

8.5 High

CVSS4

Дефекты

CWE-321