CVE-2022-25577 affects ALF-BanCO v8.2.5 and earlier, stemming from the use of a hardcoded password to encrypt its SQLite database. This critical vulnerability (CVSS 9.1) allows unauthenticated remote or local attackers to fully compromise user data, leading to high confidentiality and integrity impacts. While no public exploits or active exploitation have been observed, and community discussion is minimal, the inherent ease of exploitation due to the hardcoded credential presents a significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.2.3, <= 8.2.5CPE matchmatch criteria | cpe:2.3:a:alf-banco:alf-banco:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.