PT-2025-22354 · Itech · Ilabclient
CVE-2024-56429
·
Publicado
2025-05-21
·
Atualizado
2025-12-27
CVSS v3.1
7.7
Alta
| Vetor | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
itech iLabClient version 3.7.1
Description
The issue concerns the use of a hard-coded key
YngAYdgAE/kKZYu2F2wm6w== found in iLabClient.jar that allows local users to read or write to the database. This key is used by itech iLabClient for database access.Recommendations
For itech iLabClient version 3.7.1, consider restricting access to the database or removing the hard-coded key
YngAYdgAE/kKZYu2F2wm6w== from iLabClient.jar to prevent unauthorized access until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ilabclient