CVE-2020-16280

Unprotected Storage of Credentials

Unprotected Storage of Credentials

Publish date:

19 August 2020

Identifier:

CVE-2020-16280

Manufacturer:

Rangee GmbH

Product:

RangeeOS 8.0.4

Authors:

Andre Waldhoff and Bastian Kanbach

Description:

Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative services, domain joined users, and local administrators. To exploit the vulnerability a local attacker must have access to the underlying operating system

 

CREST
CREST STAR
CHECK IT Health Check Service
CBEST
Cyber Essentials
CESG Certified Service
First - Improving Security Together
BSI ISO 9001 FS 581360
BSI ISO 27001 IS 553326
PCI - Approved Scanning Vendor
NCSC CCSC - Assured Service Provider
ASSURE Cyber Supplier - CAA