Impact
UpSignOn for Windows prior to version 7.19.0 has a vulnerability that allows a local attacker to recover cleartext vault data from the application's process memory even after the user has locked the application. The flaw permits reading of sensitive fields such as entry names, URLs, usernames, passwords, TOTP secrets, and notes, effectively exposing all stored credentials and notes to the attacker.
Affected Systems
The affected product is Septeo IT Solutions' UpSignOn running on Windows environments. All installations using versions earlier than 7.19.0 are vulnerable, regardless of deployed platform configuration.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, denoting a medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Because it requires local access to the process and the PROCESS_VM_READ permission, the attack vector is local, and it will only be exploitable by an attacker who can execute code or otherwise gain permissions on the same machine. If the attacker can elevate privileges or bypass local security controls, they can read the memory space and retrieve all sensitive vault entries.
OpenCVE Enrichment