CVE Database
/

CVE-2025-22372

Back to search

CVE-2025-22372

Published: Apr 14, 2025

Modified: Apr 15, 2025

PUBLISHED

Description

Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileges to extract plain text passwords easily. This issue affects BASEC: from 14 Dec 2021.

VendorProductVersions

SicommNet

BASEC

affected
14 Dec 2021 - <= *

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now