CVE-2024-3543

Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:loadmaster:*:*:*:*:ltsf:*:*:*
cpe:2.3:a:progress:loadmaster:*:*:*:*:ga:*:*:*
cpe:2.3:a:progress:loadmaster:7.2.48.11:*:*:*:lts:*:*:*

History

10 Feb 2025, 15:16

Type Values Removed Values Added
References () https://kemptechnologies.com/ - () https://kemptechnologies.com/ - Product
References () https://support.kemptechnologies.com/hc/en-us/articles/25724813518605-ECS-Connection-Manager-Security-Vulnerabilities-CVE-2024-3544-and-CVE-2024-3543 - () https://support.kemptechnologies.com/hc/en-us/articles/25724813518605-ECS-Connection-Manager-Security-Vulnerabilities-CVE-2024-3544-and-CVE-2024-3543 - Product
CPE cpe:2.3:a:progress:loadmaster:*:*:*:*:ltsf:*:*:*
cpe:2.3:a:progress:loadmaster:7.2.48.11:*:*:*:lts:*:*:*
cpe:2.3:a:progress:loadmaster:*:*:*:*:ga:*:*:*
First Time Progress
Progress loadmaster
CWE CWE-522

Information

Published : 2024-05-02 14:15

Updated : 2025-02-10 15:16


NVD link : CVE-2024-3543

Mitre link : CVE-2024-3543

CVE.ORG link : CVE-2024-3543


JSON object : View

Products Affected

progress

  • loadmaster
CWE
CWE-257

Storing Passwords in a Recoverable Format

CWE-522

Insufficiently Protected Credentials