CVE-2024-26330

MEDIUM

Kape CyberGhostVPN <8.4.3.12823 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process is still open, and can be obtained by dumping the process memory and parsing it.

Scores

CVSS v3 6.5
EPSS 0.0060
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522
Status published
Published Jun 11, 2024
Tracked Since Feb 18, 2026