Home

Description

Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect client authentication.This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.

PUBLISHED Reserved 2025-09-04 | Published 2026-01-20 | Updated 2026-01-21 | Assigner SRA




HIGH: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-522 Insufficiently Protected Credentials

CWE-923 Improper Restriction of Communication Channel to Intended Endpoints

Product status

Default status
unknown

7.0.9 (semver) before 7.6.3.25808
affected

Credits

Asa Reynolds (SRA) finder

Rick Console (SRA) finder

References

sra.io/advisories third-party-advisory

cve.org (CVE-2025-58742)

nvd.nist.gov (CVE-2025-58742)

Download JSON