CVE-2023-32784
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys), or RAM dump of the entire system. The first character cannot be recovered. In 2.54, there is different API usage and/or random string insertion for mitigation.
- Keepass
- < 2.54
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 4.4% (91th percentile)
- Weakness
- CWE-319
- NVD status
- Modified
- Published
- 2023-05-15
CVE-2023-32784 at NVD
19 known exploits for CVE-2023-32784
Proof-of-concept code and exploit modules indexed by Sploitus
BruteForce-to-KeePass
KeePass-dump-py
CVE-2023-32784
keepass_dump
KeePwn
CVE-2023-32784-EXPLOIT-REPORT
keepass-password-dumper
KeePass-CVE-2023-32784-Exploitation-and-Defense
CVE-2023-32784-Exploitation
CVE-2023-32784-password-combinator-fixer
CVE-2023-32784-keepass-linux
cve-2023-32784
CVE-2023-32784-kdbxpassdmp
keepass2-password-finder
keepass-exfil-forensics
Exploit for Cleartext Transmission of Sensitive Information in Keepass
Exploit for Cleartext Transmission of Sensitive Information in Keepass
Exploit for Cleartext Transmission of Sensitive Information in Keepass
Exploit for Cleartext Transmission of Sensitive Information in Keepass