Description


A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other layers (e.g., full-disk encryption) have been enabled.

Weaknesses



CWE-256


CWE-522

CVSS impact metrics


CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

4.2 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2024-07-31T12:15:07.157Z

1 year ago

Last modified

2024-09-30T13:15:05.573Z

1 year ago