CVE Vulnerabilities

CVE-2024-42012

Insufficiently Protected Credentials

Published: Jan 22, 2025 | Modified: Feb 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the users password is compared to the users decrypted cleartext password. An attacker with Windows admin or debugging rights can therefore steal the users Blocky password and from there impersonate that local user.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Potential Mitigations

References