CVE-2024-36497 Vulnerability Details

  /     /     /  

CVE-2024-36497 Metadata Quick Info

CVE Published: 24/06/2024 | CVE Updated: 02/08/2024 | CVE Year: 2024
Source: SEC-VLab | Vendor: Faronics | Product: WINSelect (Standard + Enterprise)
Status : PUBLISHED

CVE-2024-36497 Description

The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and disable WINSelect entirely.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-312
CWE Name: CWE-312 Cleartext Storage of Sensitive Information
Source: Faronics

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-578
CAPEC Description: CAPEC-578 Disable Security Software


Source: NVD (National Vulnerability Database).