CVE Vulnerabilities

CVE-2023-6253

Insecure Storage of Sensitive Information

Published: Nov 22, 2023 | Modified: Nov 30, 2023
CVSS 3.x
6
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A saved encryption key in the Uninstaller in Digital Guardians Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Digital_guardian_agent Fortra * 7.9.4 (excluding)

References