An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 10 Jun 2025 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Itopvpn
Itopvpn dualsafe Password Manager
CPEs cpe:2.3:a:itopvpn:dualsafe_password_manager:*:*:*:*:*:*:*:*
Vendors & Products Itopvpn
Itopvpn dualsafe Password Manager

Thu, 27 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-532
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-27T19:41:19.304Z

Reserved: 2024-01-25T00:00:00.000Z

Link: CVE-2024-24272

cve-icon Vulnrichment

Updated: 2024-08-01T23:19:51.953Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-21T22:15:10.850

Modified: 2025-06-10T00:55:42.550

Link: CVE-2024-24272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.