CVE Vulnerabilities

CVE-2023-28345

Cleartext Storage of Sensitive Information

Published: May 31, 2023 | Modified: Jan 14, 2025
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teachers Console password in cleartext via an API endpoint accessible from localhost. Attackers with physical access to the Teacher Console can open a web browser, navigate to the affected endpoint and obtain the teachers password. This enables them to log into the Teacher Console and begin trivially attacking student machines.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Insight Faronics 10.0.19045 (including) 10.0.19045 (including)

Potential Mitigations

References