SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Username and Password fields.
References
Link | Resource |
---|---|
https://github.com/NF-Security-Team/CVEs/tree/main/CVE-2022-22908 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-02-26 14:15
Updated : 2022-03-07 15:03
NVD link : CVE-2022-22908
Mitre link : CVE-2022-22908
JSON object : View
CWE
CWE-522
Insufficiently Protected Credentials
Products Affected
sangfor
- vdi_client