Impact
The /api/v2/setting/adserversetting endpoint permits retrieval of the Active Directory service account credentials in cleartext via a crafted GET request. This means an attacker who can reach the endpoint can steal the credentials used by the BioStar system to authenticate against the corporate Active Directory. Stolen service account credentials can lead to full domain compromise, lateral movement, or other privilege escalation attacks. The weakness is a cleartext credential disclosure (CWE-319).
Affected Systems
Suprema BioStar 2 versions preceding 2.9.12 and Suprema BioStar X versions preceding 1.0.2 are vulnerable.
Risk and Exploitability
With a CVSS score of 7.7 the vulnerability is considered high severity. The EPSS score is < 1%, indicating a low probability of exploitation, and the issue is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. However, because the exploit path requires only a simple crafted GET request to an exposed API endpoint, the likelihood of exploitation in untrusted network environments remains significant if the API is not adequately firewalled.
OpenCVE Enrichment