CVE-2024-39206

An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to enginesettings.list being encrypted with a hard coded key.
Configurations

No configuration.

History

21 Nov 2024, 09:27

Type Values Removed Values Added
References () https://www.proactivelabs.com.au/2024/06/19/cloudberry.html - () https://www.proactivelabs.com.au/2024/06/19/cloudberry.html -

08 Jul 2024, 14:18

Type Values Removed Values Added
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

03 Jul 2024, 12:53

Type Values Removed Values Added
Summary
  • (es) Un problema descubierto en MSP360 Backup Agent v7.8.5.15 y v7.9.4.84 permite a los atacantes obtener credenciales de recursos compartidos de red utilizadas en una copia de seguridad debido a que Enginesettings.list está cifrado con una clave codificada.

02 Jul 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-02 18:15

Updated : 2024-11-21 09:27


NVD link : CVE-2024-39206

Mitre link : CVE-2024-39206

CVE.ORG link : CVE-2024-39206


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management