Cleartext storage of sensitive information in PowerPath Windows - CVE-2023-32448

 

Cleartext storage of sensitive information in PowerPath Windows - CVE-2023-32448

Published: May 26, 2023


Vulnerability identifier: #VU76583
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32448
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to the application stores its license key stored locally in clear text. A local user with access to the installation directory can retrieve the license key of the product and use it to install and license PowerPath on different systems.


Affected software

PowerPath Windows

How to mitigate CVE-2023-32448

Install updates from vendor's website.

PowerPath Windows - update to 7.2 P01

External References

Related Security Bulletins