PT-2022-24507 · Bigfix · Bigfix

Published

2022-12-22

·

Updated

2023-08-08

·

CVE-2022-38658

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions BigFix (affected versions not specified)
Description The issue affects BigFix deployments with the Notification Service installed on Windows, making them susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators using Notification Service related content from BES Support are at risk of exposing their SMTP sensitive data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2022-38658

Affected Products

Bigfix