PT-2022-21286 · Isode · Isode Swift

Published

2022-07-14

·

Updated

2022-07-20

·

CVE-2022-32389

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Isode SWIFT version 4.0.2
Description The issue allows attackers to access sensitive information, including user credentials and certificates, due to hard-coded credentials in the Registry Editor.
Recommendations For Isode SWIFT version 4.0.2, consider removing or modifying the hard-coded credentials in the Registry Editor to prevent unauthorized access. As a temporary workaround, restrict access to the Registry Editor to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-32389

Affected Products

Isode Swift