CVE-2022-22703

EUVD-2022-27846
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
stormshieldnetwork_security
2.0.0 ≤
𝑥
< 2.1.1
stormshieldnetwork_security
3.0.0 ≤
𝑥
< 3.0.2
𝑥
= Vulnerable software versions