itech iLabClient Cleartext Credentials Exposure Vulnerability

Vulnerability

A vulnerability in itech iLabClient version 3.7.1 allows local attackers to access cleartext credentials stored in the local iLabClient database. The vulnerability arises because the CONFIGS table contains unencrypted passwords for servers configured in the client. Exploitation requires establishing a connection to the local Apache Derby database used by iLabClient.

Impact

Successful exploitation of this vulnerability allows local attackers to read unencrypted passwords for servers configured in iLabClient, potentially leading to unauthorized access or actions on those servers.

Reproduction

To reproduce this vulnerability, access the local iLabClient database, which uses Apache Derby. Once connected, execute a SQL query to select the 'EINSTELLUNGEN' column from the 'configs' table. This will reveal the configuration data, including cleartext passwords. Alternatively, the provided 'get_configs.sh' script can be used to automate this process. This script must be run when no other program is accessing the database.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.