LOW · 3.3

CVE-2021-37468

NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.

Vulnerability Description

NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.

CVSS Score

3.3

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
NchReflect Customer Relationship Management<= 3.01

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-37468?

CVE-2021-37468 is a vulnerability with a CVSS score of 3.3 (LOW). NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.

How severe is CVE-2021-37468?

CVE-2021-37468 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-37468?

Check the references section above for vendor advisories and patch information. Affected products include: Nch Reflect Customer Relationship Management.