cert.plThird-party advisory
https://cert.pl/en/posts/2025/03/CVE-2024-7407 CVE-2024-7407
HIGH
Weak password encoding in Streamsoft Prestiż
Record summary
CVE-2024-7407 has a selected CVSS score of 8.2 (high).
Description
Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, which are stored in the application's database. One has to know the encoding algorithm, but it can be deduced by observing how password are transformed. This issue was fixed in 18.2.377 version of the software.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 28, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Streamsoft PrestiżBrowse Streamsoft / Streamsoft PrestiżDefault status: unaffected | CVE List | Before 18.2.377 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-7407 streamsoft.plproduct
https://www.streamsoft.pl/streamsoft-prestiz