EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system mail from the system frontend.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Please update to version 5.8.11.1.081013 or later.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Nov 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system mail from the system frontend. | |
| Title | Digiwin|EasyFlow GP - Insufficiently Protected Credentials | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-11-17T06:23:21.352Z
Reserved: 2025-11-14T03:31:47.608Z
Link: CVE-2025-13164
No data.
Status : Received
Published: 2025-11-17T08:16:22.860
Modified: 2025-11-17T08:16:22.860
Link: CVE-2025-13164
No data.
OpenCVE Enrichment
No data.