6.5
CVE-2026-23635
- EPSS 0.32%
- Veröffentlicht 25.03.2026 16:57:19
- Zuletzt bearbeitet 27.03.2026 19:16:29
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Kiteworks Secure Data Forms has a potential Unprotected Transport of Credentials
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, a misconfiguration of the security attributes could potentially lead to Unprotected Transport of Credentials under certain circumstances. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.232 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.2 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
|
| security-advisories@github.com | 6.5 | 2.2 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-523 Unprotected Transport of Credentials
Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
https://github.com/kiteworks/security-advisories/security/advisories/GHSA-9hw2-6qp4-3v8f