VulnerabilityAnalyzed
CVE-2024-3543
Use of reversible password encryption algorithm allows attackers to decrypt passwords.
HIGH 7.5EPSS 0.28%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Use of reversible password encryption algorithm allows attackers to decrypt passwords. Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-257, CWE-522
- Affected
- progress/loadmaster
- Source
- security@progress.com
References
- https://kemptechnologies.com/Product
- https://support.kemptechnologies.com/hc/en-us/articles/25724813518605-ECS-Connection-Manager-Security-Vulnerabilities-CVE-2024-3544-and-CVE-2024-3543Product
- https://kemptechnologies.com/Product
- https://support.kemptechnologies.com/hc/en-us/articles/25724813518605-ECS-Connection-Manager-Security-Vulnerabilities-CVE-2024-3544-and-CVE-2024-3543Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.