CVE-2022-22908

MEDIUM

Sangfor Vdi Client - Insufficiently Protected Credentials

Title source: rule

Description

SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Username and Password fields.

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 16.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (1)

sangfor/vdi_client

Timeline

Published Feb 26, 2022
Tracked Since Feb 18, 2026