Vulnerability Description
SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Username and Password fields.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sangfor | Vdi Client | 5.4.2.1006 |
Related Weaknesses (CWE)
References
- https://github.com/NF-Security-Team/CVEs/tree/main/CVE-2022-22908ExploitThird Party Advisory
- https://github.com/NF-Security-Team/CVEs/tree/main/CVE-2022-22908ExploitThird Party Advisory
FAQ
What is CVE-2022-22908?
CVE-2022-22908 is a vulnerability with a CVSS score of 5.5 (MEDIUM). SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Username and Password fields.
How severe is CVE-2022-22908?
CVE-2022-22908 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22908?
Check the references section above for vendor advisories and patch information. Affected products include: Sangfor Vdi Client.