5.5
CVE-2024-34113
- EPSS 0.03%
- Veröffentlicht 13.06.2024 12:15:11
- Zuletzt bearbeitet 21.11.2024 09:18:07
- Quelle psirt@adobe.com
- CVE-Watchlists
- Unerledigt
ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation that compromises the confidentiality of password data. An attacker could exploit this weakness to decrypt or guess passwords, potentially gaining unauthorized access to protected resources. Exploitation of this issue does not require user interaction.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version2021 Updateupdate1
Adobe ≫ Coldfusion Version2021 Updateupdate10
Adobe ≫ Coldfusion Version2021 Updateupdate11
Adobe ≫ Coldfusion Version2021 Updateupdate12
Adobe ≫ Coldfusion Version2021 Updateupdate13
Adobe ≫ Coldfusion Version2021 Updateupdate2
Adobe ≫ Coldfusion Version2021 Updateupdate3
Adobe ≫ Coldfusion Version2021 Updateupdate4
Adobe ≫ Coldfusion Version2021 Updateupdate5
Adobe ≫ Coldfusion Version2021 Updateupdate6
Adobe ≫ Coldfusion Version2021 Updateupdate7
Adobe ≫ Coldfusion Version2021 Updateupdate8
Adobe ≫ Coldfusion Version2021 Updateupdate9
Adobe ≫ Coldfusion Version2023 Updateupdate1
Adobe ≫ Coldfusion Version2023 Updateupdate2
Adobe ≫ Coldfusion Version2023 Updateupdate3
Adobe ≫ Coldfusion Version2023 Updateupdate4
Adobe ≫ Coldfusion Version2023 Updateupdate5
Adobe ≫ Coldfusion Version2023 Updateupdate6
Adobe ≫ Coldfusion Version2023 Updateupdate7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.057 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@adobe.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-261 Weak Encoding for Password
Obscuring a password with a trivial encoding does not protect the password.
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.