Description
Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data.

This issue affects Cryptosim: before 3.1.0.229.
Published: 2026-08-18
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from cleartext storage of sensitive data within Kriptok Crypto's Cryptosim. Because information is written to disk without encryption, an attacker who gains read access to the file system or the running process could obtain confidential data. The impact is a loss of confidentiality; the attacker cannot alter data, but can disclose it. This weakness corresponds to CWE-312.

Affected Systems

Kriptok Crypto and Information Technologies Industry Trade Inc. offers the Cryptosim tool. All versions before 3.1.0.229 are affected, so installations using those releases are susceptible. The vulnerability is tied to the Cryptosim component that allows retrieval of embedded sensitive data.

Risk and Exploitability

The CVSS base score of 5.7 classifies the flaw as a medium severity risk; the EPSS score is not available, so the computed probability of exploitation at this time is unknown, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw only exposes data that has already been stored, the attack vector is likely local or requires that an attacker can read the Cryptosim storage files or memory. Based on the description, it is inferred that exploitation would need system or privileged access and would not allow arbitrary code execution. Therefore while the potential damage is significant in terms of data confidentiality, the likelihood of exploitation remains uncertain.

Generated by OpenCVE AI on August 18, 2026 at 14:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cryptosim to version 3.1.0.229 or later to eliminate the cleartext storage issue.
  • If a version upgrade cannot be performed immediately, ensure that any sensitive data handled by Cryptosim is encrypted before storage or that it is deleted from cleartext storage as soon as possible.
  • Restrict access to the files and processes that hold embedded sensitive data, using file‑system permissions or role‑based access control, to limit who can read the exposed information.

Generated by OpenCVE AI on August 18, 2026 at 14:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Kriptok Crypto
Kriptok Crypto cryptosim
Vendors & Products Kriptok Crypto
Kriptok Crypto cryptosim

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryptosim: before 3.1.0.229.
Title Sensitive Data Exposure in Kriptek Crypto's Cryptosim
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Kriptok Crypto Cryptosim
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-18T13:26:55.598Z

Reserved: 2026-03-31T12:19:32.337Z

Link: CVE-2026-5224

cve-icon Vulnrichment

Updated: 2026-08-18T13:26:25.309Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T12:19:28.170

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-5224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:39:13Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information