CVE-2026-31278
7.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Summary
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| supremainc | BioStar 2 | 0 < 2.9.12 | affected |
Weaknesses
- CWE-319: CWE-319 Cleartext Transmission of Sensitive Information
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.