7.7
CVE-2026-31278
- EPSS 0.15%
- Veröffentlicht 14.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 20:00:03
- Erkennungen
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellersupremainc
≫
Produkt
BioStar 2
Default Statusunaffected
Version
0
Version <
2.9.12
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.046 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 7.7 | 3.1 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
https://www.supremainc.com
https://github.com/mda1r/biostar2-ad-credential-exposure
https://github.com/mda1r/CVE-2026-31278