CVE-2025-22372
Severity CVSS v4.0:
CRITICAL
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
14/04/2025
Last modified:
15/04/2025
Description
Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery.<br />
Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileges to extract plain text passwords easily.<br />
<br />
This issue affects BASEC: from 14 Dec 2021.



