Impact
QND uses a hard‑coded cryptographic key. A user who is logged into a Windows PC where the client is installed can use that key to derive administrator credentials, such as an ID and password. This weakness is a form of in‑source cryptographic key storage (CWE‑321).
Affected Systems
The vulnerability affects QualitySoft Corporation’s QND Advance, QND Premium, and QND Standard products. No specific versions are listed, so any installed client should be considered at risk.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity and the EPSS score of less than 1% suggests a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local on a Windows PC, where an attacker must already be logged in. If successful, the attacker can obtain administrator credentials.
OpenCVE Enrichment