CVE-2017-15918

HIGH

Ignitum Sera - Insufficiently Protected Credentials

Title source: rule
STIX 2.1

Description

Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user and system keychains to local attacks.

Exploits (1)

exploitdb WORKING POC
by Mark Wadham · bashlocalmacos
https://www.exploit-db.com/exploits/43221

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43221/

Scores

CVSS v3 7.8
EPSS 0.0026
EPSS Percentile 48.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (1)
ignitum/sera 1.2 (2 CPE variants)
Published Nov 01, 2017
Tracked Since Feb 18, 2026