Impact
The vulnerability arises from cleartext storage of sensitive data within Kriptok Crypto's Cryptosim. Because information is written to disk without encryption, an attacker who gains read access to the file system or the running process could obtain confidential data. The impact is a loss of confidentiality; the attacker cannot alter data, but can disclose it. This weakness corresponds to CWE-312.
Affected Systems
Kriptok Crypto and Information Technologies Industry Trade Inc. offers the Cryptosim tool. All versions before 3.1.0.229 are affected, so installations using those releases are susceptible. The vulnerability is tied to the Cryptosim component that allows retrieval of embedded sensitive data.
Risk and Exploitability
The CVSS base score of 5.7 classifies the flaw as a medium severity risk; the EPSS score is not available, so the computed probability of exploitation at this time is unknown, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw only exposes data that has already been stored, the attack vector is likely local or requires that an attacker can read the Cryptosim storage files or memory. Based on the description, it is inferred that exploitation would need system or privileged access and would not allow arbitrary code execution. Therefore while the potential damage is significant in terms of data confidentiality, the likelihood of exploitation remains uncertain.
OpenCVE Enrichment