Cleartext storage of sensitive information in Expedition - CVE-2024-9466

 

Cleartext storage of sensitive information in Expedition - CVE-2024-9466

Published: October 11, 2024 / Updated: October 22, 2024


Vulnerability identifier: #VU98386
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9466
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to firewall usernames, passwords, and API keys generated using those credentials are stored in plain text on the system. A local user can obtain credentials of other users.



Affected software

Expedition

How to mitigate CVE-2024-9466

Install updates from vendor's website.

Expedition - update to 1.2.96

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins