nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-9203 CVE-2024-9203
LOW
Enpass Password Manager sensitive information in memory
Record summary
CVE-2024-9203 has a selected CVSS score of 2.0 (low).
Description
A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information in memory. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 6.10.1 is able to address this issue. It is recommended to upgrade the affected component.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Password ManagerBrowse Enpass / Password Manager | CVE List | 6.9.0 | affected |
| 6.9.1 | affected | ||
| 6.9.2 | affected | ||
| 6.9.3 | affected | ||
| 6.9.4 | affected | ||
| 6.9.5 | affected |
References
5VDB-278561 | CTI Indicators (IOB, IOC, TTP)signaturepermissions required
https://vuldb.com/?ctiid.278561 VDB-278561 | Enpass Password Manager sensitive information in memoryvdb entry
https://vuldb.com/?id.278561 Submit #411207 | Enpass Password Manager Windows 10 Cleartext Storage of Sensitive Information in MemoryThird-party advisory
https://vuldb.com/?submit.411207 enpass.iopatch
https://www.enpass.io/release-notes/windows-10-desktop