CyberRota Analysis
AI-GeneratedVSee Clinic versions 7.1.26 and API 1.3.0 expose cleartext SFTP credentials in HTTP responses from three unauthenticated endpoints, potentially allowing remote attackers to access sensitive SFTP servers without authentication. Organizations using these versions, especially those with SFTP configured, should prioritize addressing this vulnerability to prevent unauthorized access to their data. Immediate remediation is essential to mitigate the risk of credential theft and subsequent exploitation.
Original NVD Description
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.
Related CVEs
Other vulnerabilities affecting the same vendor(s)