PT-2018-10495 · Intuit · Intuit Lacerte
User
·
Published
2018-07-31
·
Updated
2024-02-14
·
CVE-2018-11338
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Intuit Lacerte version 2017
Intuit Lacerte versions prior to 2017
Description
The software transfers the entire customer list in cleartext over SMB, allowing attackers to obtain sensitive information by sniffing the network or conduct man-in-the-middle (MITM) attacks. The customer list contains sensitive information such as full name, social security number, address, job title, phone number, email address, and other sensitive details. After the client software authenticates to the server database, the server sends the customer list, exposing all sensitive data without needing further exploitation.
Recommendations
For Intuit Lacerte version 2017, consider implementing encryption for data transferred over SMB to protect sensitive customer information.
For Intuit Lacerte versions prior to 2017, apply the same encryption measures as for version 2017 to mitigate the risk of sensitive data exposure.
As a temporary workaround, consider restricting access to the customer list until a more secure data transfer method is implemented.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intuit Lacerte