Vulnerabilities (CVE)

Filtered by CWE-316
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-23349 2024-03-22 N/A 2.2 LOW
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the saved credentials, and the KPM extension must autofill these credentials. The attacker must then launch a malware module to steal those specific credentials.
CVE-2022-46141 1 Siemens 1 Simatic Step 7 2023-12-15 N/A 5.5 MEDIUM
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the access level password of the SIMATIC S7-1200 and S7-1500 CPUs, when entered by a legitimate user in the hardware configuration of the affected application.
CVE-2023-40724 1 Siemens 1 Qms Automotive 2023-12-10 N/A 7.3 HIGH
A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as plaintext. An attacker could perform a memory dump, and get access to credentials, and use it for impersonation.