SB2022011301 - Missing Encryption of Sensitive Data in PASSWORD MANAGER "MIRUPASS" PW10 / PW20
Published: January 13, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Encryption of Sensitive Data (CVE-ID: CVE-2022-0183)
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to an inappropriate encryption algorithm. An attacker with physical access can obtain the stored passwords.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.