PT-2020-13560 · Nch · Express Accounts

Tejas Nitin Pingulkar

·

Published

2020-12-28

·

Updated

2020-12-30

·

CVE-2020-13473

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NCH Express Accounts versions 8.24 and earlier
Description The issue allows local users to discover the cleartext password by reading the configuration file.
Recommendations For versions 8.24 and earlier, consider restricting access to the configuration file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13473

Affected Products

Express Accounts