PT-2022-7097 · Pcvue · Pcvue

Arc Informatique

·

Published

2022-12-12

·

Updated

2023-07-06

·

CVE-2022-4312

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PcVue versions 8.10 through 15.2.3
Description A cleartext storage of sensitive information issue exists, allowing an unauthorized user with access to the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer protocol (SMTP) account credentials and the SIM card PIN code. Successful exploitation could allow an unauthorized user access to the underlying email account and SIM card.
Recommendations For PcVue versions 8.10 through 15.2.3, consider restricting access to the email and SMS accounts configuration files to minimize the risk of exploitation. As a temporary workaround, restrict access to sensitive information stored in cleartext until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2023-07572
CVE-2022-4312

Affected Products

Pcvue