Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring. This issue affects SecHard: before 3.3.0.20220411.
The SecHard product improperly uses privileged APIs (CWE-648), which allows an attacker to manipulate interfaces and abuse authentication mechanisms. Additionally, sensitive data, including credentials, are transmitted in unencrypted form (CWE-319), which enables their interception on the local network. Insufficient protection of stored and transmitted authentication credentials (CWE-522) further facilitates their acquisition through API event monitoring.
An attacker with access to the local network and basic privileges can bypass authentication mechanisms, manipulate system interfaces, and obtain credentials of other users — which can ultimately lead to full system takeover (violation of confidentiality, integrity, and availability).
Update SecHard to version 3.3.0.20220411 or later. Detailed information is available in the manufacturer's references and in bulletin TR-25-0074 published by USOM.
SecHard (Sechard Information Technologies) in all versions prior to 3.3.0.20220411.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H