CVE-2018-10814 describes a critical vulnerability in Synametrics SynaMan 4.0 build 1488, where SMTP credentials are stored in cleartext. This flaw, rated with a CVSS score of 7.8 (HIGH), allows a local, low-privileged attacker to easily access sensitive authentication information, leading to high impact on confidentiality, integrity, and availability. While not observed in active exploitation and not on the CISA KEV list, a public exploit (EDB-45387) exists, demonstrating its exploitability. Despite the available exploit, there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:synametrics:synaman:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.