CVE Vulnerabilities

CVE-2018-17613

Insufficiently Protected Credentials

Published: Sep 28, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Telegram Desktop (aka tdesktop) 1.3.16 alpha, when Use proxy is enabled, sends credentials and application data in cleartext over the SOCKS5 protocol.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Telegram_desktopTelegram1.3.16-alpha (including)1.3.16-alpha (including)
Telegram-desktopUbuntubionic*
Telegram-desktopUbuntucosmic*
Telegram-desktopUbuntudisco*
Telegram-desktopUbuntueoan*
Telegram-desktopUbuntufocal*
Telegram-desktopUbuntugroovy*
Telegram-desktopUbuntuhirsute*
Telegram-desktopUbuntuimpish*
Telegram-desktopUbuntukinetic*

Potential Mitigations

References