Cleartext Password Exposure in Faronics Insight Teacher Console on Windows
CVE-2023-28345

4.6MEDIUM

Key Information:

Vendor

Faronics

Status
Vendor
CVE Published:
31 May 2023

What is CVE-2023-28345?

Faronics Insight version 10.0.19045 for Windows contains a vulnerability in the Teacher Console application that exposes the console password in cleartext through an API endpoint accessible from localhost. This flaw allows users with physical access to the Teacher Console to exploit the endpoint, using a web browser to retrieve the teacher's password. Once obtained, this password permits unauthorized access to the Teacher Console, potentially enabling attackers to compromise student machines with minimal effort.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-28345 : Cleartext Password Exposure in Faronics Insight Teacher Console on Windows