Missing Encryption of Sensitive Data in PASSWORD MANAGER "MIRUPASS" PW10 and PASSWORD MANAGER "MIRUPASS" PW20 - CVE-2022-0183

 

Missing Encryption of Sensitive Data in PASSWORD MANAGER "MIRUPASS" PW10 and PASSWORD MANAGER "MIRUPASS" PW20 - CVE-2022-0183

Published: January 13, 2022


Vulnerability identifier: #VU59571
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0183
CWE-ID: CWE-311
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to an inappropriate encryption algorithm. An attacker with physical access can obtain the stored passwords.


Affected software

PASSWORD MANAGER "MIRUPASS" PW10
PASSWORD MANAGER "MIRUPASS" PW20

How to mitigate CVE-2022-0183

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins