Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, which are stored in the application's database. One has to know the encoding algorithm, but it can be deduced by observing how password are transformed.  This issue was fixed in 18.2.377 version of the software.
History

Fri, 28 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Description Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, which are stored in the application's database. One has to know the encoding algorithm, but it can be deduced by observing how password are transformed.  This issue was fixed in 18.2.377 version of the software.
Title Weak password encoding in Streamsoft Prestiż
Weaknesses CWE-261
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-03-28T13:40:49.121Z

Reserved: 2024-08-02T09:50:51.479Z

Link: CVE-2024-7407

cve-icon Vulnrichment

Updated: 2025-03-28T13:40:45.983Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-28T13:15:40.760

Modified: 2025-03-28T18:11:40.180

Link: CVE-2024-7407

cve-icon Redhat

No data.