PT-2025-22354 · Itech · Ilabclient

CVE-2024-56429

·

Publicado

2025-05-21

·

Atualizado

2025-12-27

CVSS v3.1

7.7

Alta

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions itech iLabClient version 3.7.1
Description The issue concerns the use of a hard-coded key YngAYdgAE/kKZYu2F2wm6w== found in iLabClient.jar that allows local users to read or write to the database. This key is used by itech iLabClient for database access.
Recommendations For itech iLabClient version 3.7.1, consider restricting access to the database or removing the hard-coded key YngAYdgAE/kKZYu2F2wm6w== from iLabClient.jar to prevent unauthorized access until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-56429

Produtos afetados

Ilabclient