Password Encoding Vulnerability in Streamsoft Prestiż Software
CVE-2024-7407

8.2HIGH

Key Information:

Vendor

Streamsoft

Vendor
CVE Published:
28 March 2025

What is CVE-2024-7407?

A vulnerability in Streamsoft Prestiż software arises from the use of a custom password encoding algorithm. This allows attackers to easily decode enciphered passwords stored in the application’s database. Although knowledge of the encoding algorithm is required, it can often be inferred by analyzing the transformation patterns of the passwords. The issue has been addressed in version 18.2.377 of the software.

Affected Version(s)

Streamsoft Prestiż 0 < 18.2.377

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil Dąbkowski
.