VulnerabilityModified
CVE-2022-36617
This issue allows attackers with administrative privileges to recover cleartext passwords.
MEDIUM 4.9EPSS 0.51%
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- haystacksoftware/arq backup
- Source
- cve@mitre.org
References
- https://startrekdude.github.io/arqbackup.htmlMailing List, Third Party Advisory
- https://www.arqbackup.com/download/arqbackup/arq7windows_release_notes.htmlRelease Notes, Vendor Advisory
- https://startrekdude.github.io/arqbackup.htmlMailing List, Third Party Advisory
- https://www.arqbackup.com/download/arqbackup/arq7windows_release_notes.htmlRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.