EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system mail from the system frontend.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Nov 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Digiwin
Digiwin easyflow Gp |
|
| Vendors & Products |
Digiwin
Digiwin easyflow Gp |
Mon, 17 Nov 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system mail from the system frontend. | |
| Title | Digiwin|EasyFlow GP - Insufficiently Protected Credentials | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published: 2025-11-17T06:23:21.352Z
Updated: 2025-11-17T16:19:24.139Z
Reserved: 2025-11-14T03:31:47.608Z
Link: CVE-2025-13164
Updated: 2025-11-17T16:19:19.700Z
Status : Awaiting Analysis
Published: 2025-11-17T08:16:22.860
Modified: 2025-11-18T14:06:29.817
Link: CVE-2025-13164
No data.