vendor:
PrivateTunnel Client
by:
Yakir Wizman, Viktor Minin
6,4
CVSS
MEDIUM
Local Credentials Disclosure
N/A
CWE
Product Name: PrivateTunnel Client
Affected Version From: 2.7.0
Affected Version To: 2.7.0
Patch Exists: NO
Related CWE: N/A
CPE: privatetunnel:privatetunnel_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 64bit
2016
PrivateTunnel Client v2.7.0 (x64) Local Credentials Disclosure After Sign out Exploit
PrivateTunnel Client v2.7.0 is vulnerable to local credentials disclosure after the user is logged out. It seems that PrivateTunnel does store the supplied credentials while the user is logged in and after sign out in a plaintext format in memory process. A potential attacker could reveal the supplied username and password in order to gain access to PrivateTunnel account.
Mitigation:
N/A