vendor:
TSPlus
by:
Carlo Di Dato for Deloitte Risk Advisory Italia
7.5
CVSS
HIGH
Insecure Credential Storage
257
CWE
Product Name: TSPlus
Affected Version From: Up to 16.0.0.0
Affected Version To: Up to 16.0.0.0
Patch Exists: NO
Related CWE: CVE-2023-31069
CPE: a:tsplus:tsplus:16.0.0.0
Platforms Tested: Windows
2023
TSPlus 16.0.0.0 – Remote Work Insecure Credential storage
With TSPlus Remote Work (v. 16.0.0.0) you can create a secure single sign-on web portal and remote desktop gateway that enables users to remotely access the console session of their office PC. It is possible to create a custom web portal login page which allows a user to login without providing their credentials. However, the credentials are stored in an insecure manner since they are saved in cleartext, within the html login page. This means that everyone with an access to the web login page can easily retrieve the credentials to access the application by simply looking at the html code page.
Mitigation:
To mitigate this vulnerability, the vendor should implement secure password storage techniques such as hashing and salting. Users should also be advised to use unique and complex passwords.