CVE-2024-7407 is a high-severity vulnerability (CVSS 8.2) affecting Streamsoft Prestiż software, where a custom, easily reversible password encoding algorithm allows for straightforward decoding of user passwords stored in the application's database. This flaw, categorized as CWE-261 (Insufficient Authentication), could lead to unauthorized access to sensitive information. The attack requires network access but has low complexity, as the encoding algorithm can be deduced. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low current threat landscape. The issue has been patched in version 18.2.377 of Streamsoft Prestiż.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Streamsoft | Streamsoft Prestiż | >= 0, < 18.2.377CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.