CyberRota Analysis
AI-GeneratedThe Suprema BioStar 2 and BioStar X systems prior to specified versions are vulnerable due to a flaw in the /api/v2/setting/adserversetting endpoint, which allows attackers to retrieve Active Directory service account credentials in cleartext through a specially crafted GET request. This poses a significant risk as it can lead to unauthorized access and potential compromise of the entire Active Directory environment. Organizations utilizing these systems should prioritize patching to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.