CVE-2022-25577

ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user's data. Attackers who are able to gain remote or local access to the system are able to read and modify the data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:alf-banco:alf-banco:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:52

Type Values Removed Values Added
References () https://github.com/ph0nkybit/proof-of-concepts/tree/main/Use_Of_Hardcoded_Password_In_ALF-BanCO_8.2.x - Exploit, Third Party Advisory () https://github.com/ph0nkybit/proof-of-concepts/tree/main/Use_Of_Hardcoded_Password_In_ALF-BanCO_8.2.x - Exploit, Third Party Advisory

31 Mar 2022, 01:17

Type Values Removed Values Added
CWE CWE-798
CPE cpe:2.3:a:alf-banco:alf-banco:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.4
v3 : 9.1
References (MISC) https://github.com/ph0nkybit/proof-of-concepts/tree/main/Use_Of_Hardcoded_Password_In_ALF-BanCO_8.2.x - (MISC) https://github.com/ph0nkybit/proof-of-concepts/tree/main/Use_Of_Hardcoded_Password_In_ALF-BanCO_8.2.x - Exploit, Third Party Advisory

25 Mar 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-25 17:15

Updated : 2024-11-21 06:52


NVD link : CVE-2022-25577

Mitre link : CVE-2022-25577

CVE.ORG link : CVE-2022-25577


JSON object : View

Products Affected

alf-banco

  • alf-banco
CWE
CWE-798

Use of Hard-coded Credentials