Clear-text passwords in configuration files
CVE-2022-4308

8.8HIGH

Key Information:

Vendor

Secomea

Vendor
CVE Published:
19 April 2023

What is CVE-2022-4308?

The Secomea GateManager's USB wizard is susceptible to a vulnerability that allows for the insecure storage of passwords in plaintext. This can lead to potential authentication abuse on the SiteManager if sensitive generated files are inadvertently leaked. It is critical for users to implement stringent security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

GateManager Linux 5.0 < 10.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.