logo

214 Business information leak - Credentials


Description

A leaked account gives attackers instant access to sensitive data or internal systems. Can be used to compromise customer and employee data, financial records, intellectual property and other sensitive information that could leave you at great risk.


Impact

- Attempt to compromise the account that the credentials leaked from. - Leverage credentials from one application to compromise additional ones.


Recommendation

- Enable multi-factor authentication on business accounts to add an extra layer of security. - Ensure strong passwords creation and management. - Establish security policies warranting restrictions and penalties concerning to the use of work related credentials. - Network security and access controls should be reviewed.


Threat

Unauthorized attacker with access to business information.


Expected Remediation Time

60 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: N
  • Attack complexity: L
  • Attack Requirements: N
  • Privileges required: N
  • User interaction: N
  • Confidentiality (VC): L
  • Integrity (VI): L
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/02/16