vendor:
Protege GX/WX
by:
LiquidWorm
7.5
CVSS
HIGH
Client-Side Password Hash Disclosure
798
CWE
Product Name: Protege GX/WX
Affected Version From: GX: Ver: 2.08.1002 K1B3 Lib: 04.00.217 Int: 2.3.235.J013 OS: 2.0.20 WX: Ver: 4.00 284 H062 App: 02.08.766 Lib: 04.00.169 Int: 02.2.208
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Microsoft-WinCE/6.00
2022
ICT Protege GX/WX 2.08 – Client-Side SHA1 Password Hash Disclosure
The application is vulnerable to improper access control that allows an authenticated operator to disclose SHA1 password hashes (client-side) of other users/operators.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability at the time of writing this advisory. It is recommended to restrict access to the vulnerable application and ensure proper access control measures are in place.