9.8
CVE-2018-17613
- EPSS 0.31%
- Veröffentlicht 28.09.2018 10:29:15
- Zuletzt bearbeitet 21.11.2024 03:54:42
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protocol.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Telegram ≫ Telegram Desktop Version1.3.16 Updatealpha
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.507 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.