CVE Vulnerabilities

CVE-2017-15918

Insufficiently Protected Credentials

Published: Nov 01, 2017 | Modified: Oct 03, 2019
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Sera 1.2 stores the users login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user and system keychains to local attacks.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Sera Ignitum 1.2 (including) 1.2 (including)

Potential Mitigations

References