CVE-2025-22372

Severity CVSS v4.0:
CRITICAL
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
14/04/2025
Last modified:
15/04/2025

Description

Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery.<br /> Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileges to extract plain text passwords easily.<br /> <br /> This issue affects BASEC: from 14 Dec 2021.