Impact
A memory leak flaw in Tobit Laboratories AG’s TeamDavid Webbox lets any network user retrieve private data from the server without authentication. By repeatedly requesting the endpoint "/.well-known/mta-sts.", the application returns bytes from memory that may contain user passwords and other confidential information. This flaw allows an attacker to exfiltrate credentials and other sensitive data, potentially leading to account compromise and broader system infiltration.
Affected Systems
The vulnerability affects the TeamDavid Webbox version managed through Rollout 524. No other versions are listed as affected in the current advisory.
Risk and Exploitability
The CVSS score of 9.2 marks the issue as critical. Because authentication is not required, an attacker can exploit the flaw from any system that can reach the vulnerable URL, making remote exploitation straightforward. The EPSS score is not available, but the high CVSS suggests a strong likelihood of exploitation. The vulnerability is not yet in the CISA KEV list, but the impact warrants immediate attention.
OpenCVE Enrichment