CVE-2022-22908
MEDIUMSangfor Vdi Client - Insufficiently Protected Credentials
Title source: ruleDescription
SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Username and Password fields.
Scores
CVSS v3
5.5
EPSS
0.0005
EPSS Percentile
16.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
Status
published
Affected Products (1)
sangfor/vdi_client
Timeline
Published
Feb 26, 2022
Tracked Since
Feb 18, 2026