Hardcoded DES Key Vulnerability in IGEL Universal Management Suite
CVE-2022-25807
5.5MEDIUM
What is CVE-2022-25807?
An issue exists in the IGEL Universal Management Suite (UMS) 6.07.100 where a hardcoded DES key in the LDAPDesPWEncrypter class compromises the security of encrypted LDAP bind credentials. An attacker with access to these credentials can exploit the static 8-byte DES key to decrypt sensitive information, potentially leading to unauthorized access and data leakage.
