CVE-2023-28345 describes a cleartext password vulnerability in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console exposes the teacher's password via a localhost API endpoint. An attacker with physical access to the Teacher Console can retrieve this password, enabling them to log in and potentially compromise student machines. The vulnerability has a CVSS score of 4.6 (Medium), indicating a low attack complexity but high confidentiality impact, as it requires physical access to the affected device. While the EPSS score is very low, the FAUCET Risk Score is 13/100. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, or entries in ExploitDB. The vulnerability has received no community discussion or media coverage, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0.19045CPE matchmatch criteria | cpe:2.3:a:faronics:insight:10.0.19045:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.