CVE-2022-4610

A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected by this issue is some unknown functionality. The manipulation leads to risky cryptographic algorithm. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-216272.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:clickstudios:passwordstate:*:*:*:*:*:*:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9500:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9512:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9519:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9531:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9533:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9535:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9583:*:*:*:-:*:*

Configuration 2 (hide)

cpe:2.3:a:clickstudios:passwordstate:9.5.8.4:*:*:*:*:chrome:*:*

History

23 Dec 2022, 21:28

Type Values Removed Values Added
First Time Clickstudios
Clickstudios passwordstate
References (N/A) https://vuldb.com/?id.216272 - (N/A) https://vuldb.com/?id.216272 - Third Party Advisory
References (N/A) https://www.modzero.com/static/MZ-22-03_Passwordstate_Security_Disclosure_Report-v1.0.pdf - (N/A) https://www.modzero.com/static/MZ-22-03_Passwordstate_Security_Disclosure_Report-v1.0.pdf - Exploit, Third Party Advisory
References (N/A) https://modzero.com/modlog/archives/2022/12/19/better_make_sure_your_password_manager_is_secure/index.html - (N/A) https://modzero.com/modlog/archives/2022/12/19/better_make_sure_your_password_manager_is_secure/index.html - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-310
CPE cpe:2.3:a:clickstudios:passwordstate:9.5:build_9512:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5.8.4:*:*:*:*:chrome:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9500:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9519:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9583:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9531:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9533:*:*:*:-:*:*
cpe:2.3:a:clickstudios:passwordstate:*:*:*:*:*:*:*:*
cpe:2.3:a:clickstudios:passwordstate:9.5:build_9535:*:*:*:-:*:*

19 Dec 2022, 16:52

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-19 15:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-4610

Mitre link : CVE-2022-4610

CVE.ORG link : CVE-2022-4610


JSON object : View

Products Affected

clickstudios

  • passwordstate
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-310

Cryptographic Issues