CVE-2022-22908: Medium severity sangfor vdi client vulnerability
Published Feb 26, 2022
·Updated
SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Username and Password fields.
Affected Software
1 affected component
Sangfor VDI Client=5.4.2.1006
Event History
Feb 26, 2022
CVE Published
via MITRE·09:24 PM
Data Sourced
via MITRE·09:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-22908?
CVE-2022-22908 is considered a high severity vulnerability due to the potential exposure of sensitive user credentials.
2
How do I fix CVE-2022-22908?
To mitigate CVE-2022-22908, upgrade to a secure version of Sangfor VDI Client that contains the latest security patches.
3
What type of vulnerability is CVE-2022-22908?
CVE-2022-22908 is a memory disclosure vulnerability that allows unauthorized access to sensitive data.
4
Who is affected by CVE-2022-22908?
Users of Sangfor VDI Client version 5.4.2.1006 are affected by CVE-2022-22908.
5
What can attackers gain from CVE-2022-22908?
Attackers exploiting CVE-2022-22908 can gain access to user credentials, including usernames and passwords.