Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-18466

Опубликовано: 21 мар. 2019
Источник: nvd
CVSS3: 7
CVSS2: 1.9
EPSS Низкий

Описание

An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the application stores the emergency credentials in cleartext in the logs (present in the DEBUG folder) that can be accessed by anyone. NOTE: The vendor disputes this as a vulnerability since the disclosure of a local account password (actually an alpha numeric passcode) is achievable only when a custom registry key is added to the windows registry. This action requires administrator access and the registry key is only provided by support staff at securenvoy to troubleshoot customer issues.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:securenvoy:securaccess:9.3.502:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00139
Низкий

7 High

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 7
github
больше 3 лет назад

** DISPUTED ** An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the application stores the emergency credentials in cleartext in the logs (present in the DEBUG folder) that can be accessed by anyone. NOTE: The vendor disputes this as a vulnerability since the disclosure of a local account password (actually an alpha numeric passcode) is achievable only when a custom registry key is added to the windows registry. This action requires administrator access and the registry key is only provided by support staff at securenvoy to troubleshoot customer issues.

EPSS

Процентиль: 34%
0.00139
Низкий

7 High

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-532