Vulnerabilities > Starface

DATE CVE VULNERABILITY TITLE RISK
2023-06-15 CVE-2023-33243 Use of Password Hash With Insufficient Computational Effort vulnerability in Starface 7.3.0.10
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password.
network
high complexity
starface CWE-916
8.1
2020-04-02 CVE-2020-10515 Uncontrolled Search Path Element vulnerability in Starface Unified Communication & Collaboration Client
STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.
network
low complexity
starface CWE-427
critical
9.8