CVE-2024-36497

June 24, 2024, 12:57 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

WINSelect

Source

551230f0-3615-47bd-b7cc-93e92e730bbf

Tags

CVE-2024-36497 details

Published : June 24, 2024, 9:15 a.m.
Last Modified : June 24, 2024, 12:57 p.m.

Description

The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and disable WINSelect entirely.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-312 Cleartext Storage of Sensitive Information The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

References

URL Source
https://r.sec-consult.com/winselect 551230f0-3615-47bd-b7cc-93e92e730bbf
https://www.faronics.com/en-uk/document-library/document/winselect-standard-release-notes 551230f0-3615-47bd-b7cc-93e92e730bbf
This website uses the NVD API, but is not approved or certified by it.