6

CVE-2023-6253

Exploit

Saved Uninstall Key in Digital Guardian Agent Uninstaller

A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FortraDigital Guardian Agent Version < 7.9.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.22
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6 0.8 5.2
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CWE-922 Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

http://packetstormsecurity.com/files/175956/Fortra-Digital-Guardian-Agent-Uninstaller-Cross-Site-Scripting-UninstallKey-Cached.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2023/Nov/14
Third Party Advisory
Exploit
Mailing List
https://r.sec-consult.com/fortra
Third Party Advisory
Exploit
https://www.fortra.com/security
Product