CVE-2007-2883
Credant Mobile Guardian Shield for Windows 5.2.1.105 and earlier stores account names and passwords in plaintext in memory, which allows local users to obtain sensitive information by (1) reading the paging file or (2) dumping and searching the memory…
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
Credant Mobile Guardian Shield for Windows 5.2.1.105 and earlier stores account names and passwords in plaintext in memory, which allows local users to obtain sensitive information by (1) reading the paging file or (2) dumping and searching the memory image. NOTE: This issue crosses privilege boundaries because the product is intended to protect the data on a stolen computer.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.33% probability · 27th percentile
- CISA KEV
- Not listed
- Affected
- credant/credant mobile guardian shield - windows
- Source
- cve@mitre.org
References
- http://osvdb.org/36524
- http://secunia.com/advisories/25410
- http://securityreason.com/securityalert/2753
- http://www.kb.cert.org/vuls/id/821865US Government Resource
- http://www.securityfocus.com/archive/1/469486/100/0/threaded
- http://www.securityfocus.com/bid/24139Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34487
- http://osvdb.org/36524
- http://secunia.com/advisories/25410
- http://securityreason.com/securityalert/2753
- http://www.kb.cert.org/vuls/id/821865US Government Resource
- http://www.securityfocus.com/archive/1/469486/100/0/threaded
- http://www.securityfocus.com/bid/24139Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34487
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.