Impact
The vulnerability allows an attacker to retrieve SFTP credentials from cleartext within the HTTP responses of three unauthenticated endpoints of VSee Clinic. As a result, the attacker can access the configured SFTP server without needing any authentication to the application, exposing confidential data and permitting potential file manipulation. The weakness is an information‑exposure flaw coupled with cleartext storage, corresponding to CWE‑201 and CWE‑312.
Affected Systems
VSee:Clinic version 7.1.26 and VSee:Clinic API version 1.3.0 are affected. Both vendor and product names are confirmed by the CNA Affected Vendor/Product list.
Risk and Exploitability
The CVSS score of 9 indicates a critical severity. EPSS score is less than 1% (≈0.26%), and the vulnerability is not listed in the CISA KEV catalog. Because no authentication is required to retrieve the credentials, exploitation can occur from any network that can reach the vulnerable endpoints. An attacker can immediately obtain the SFTP credentials and use them to access the configured SFTP server, compromising confidentiality and integrity of data stored there. The likely attack vector is inferred from the fact that the endpoints are reachable over HTTP without authentication, implying that a remote attacker can exploit the issue from outside the application.
OpenCVE Enrichment