Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in /Users/user/Library/Application Support/ntfs-tool/config.json.
History

Tue, 18 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Mar 2025 11:30:00 +0000

Type Values Removed Values Added
Description Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in /Users/user/Library/Application Support/ntfs-tool/config.json.
Title Insecure storage of sensitive information in NTFS Tool
Weaknesses CWE-922
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-03-18T13:06:22.200Z

Reserved: 2025-03-18T08:48:06.830Z

Link: CVE-2025-2489

cve-icon Vulnrichment

Updated: 2025-03-18T13:06:16.859Z

cve-icon NVD

Status : Received

Published: 2025-03-18T12:15:15.770

Modified: 2025-03-18T12:15:15.770

Link: CVE-2025-2489

cve-icon Redhat

No data.