6.5

CVE-2024-33901

Exploit
Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KeepassxcKeepassxc Version2.7.7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.7% 0.482
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-316 Cleartext Storage of Sensitive Information in Memory

The product stores sensitive information in cleartext in memory.

https://gist.github.com/Fastor01/30c6d89c842feb1865ec2cd2d3806838
Exploit
https://github.com/keepassxreboot/keepassxc/issues/10784
Issue Tracking
https://keepassxc.org/blog/
Release Notes
https://keepassxc.org/blog/2019-02-21-memory-security/
Product