PT-2024-21354 · Kape · Cyberghostvpn

Maximilian Barz

·

Published

2024-06-11

·

Updated

2024-11-01

·

CVE-2024-26330

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kape CyberGhostVPN version 8.4.3.12823
Description An issue was discovered where user credentials remain in memory after a successful logout, while the process is still open. These credentials can be obtained by dumping the process memory and parsing it.
Recommendations For Kape CyberGhostVPN version 8.4.3.12823, as a temporary workaround, consider closing the application process after logout to minimize the risk of credential exposure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-26330

Affected Products

Cyberghostvpn