Impact
UpSignOn for Windows versions prior to 7.19.0 contains a flaw that lets a local attacker recover the master password by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re‑locked. By extracting the backup key from memory, the attacker can decrypt the encrypted master password backup stored in v6-vault1.DATA.txt and then use that master password to decrypt the main vault and export all stored password manager entries in clear text. This vulnerability is categorized as sensitive data exposure (CWE‑316).
Affected Systems
The vulnerability affects Septeo IT Solutions' UpSignOn product on Windows. All UpSignOn installations with a version number lower than 7.19.0 are vulnerable. No additional affected versions are listed beyond the pre‑7.19.0 threshold.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, but the vulnerability requires local access to the machine running UpSignOn.exe. An attacker who can read process memory—such as a user with administrative privileges or one who can execute memory‑dumping tools—can exploit the flaw. The exploitation does not require network access or remote code execution; it is limited to local attackers with sufficient privileges. The lack of an EPSS score and the absence from the CISA KEV catalog suggest that while the vulnerability is not currently widely exploited, it presents a significant risk if local access is achieved.
OpenCVE Enrichment