PT-2024-16715 · Unknown · Intelligent Apps Freenow App

Secuserx

·

Published

2024-11-08

·

Updated

2024-11-23

·

CVE-2024-11026

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Intelligent Apps Freenow App version 12.10.0
Description A problem was found in the Intelligent Apps Freenow App, affecting some unknown functionality of the file ch/qos/logback/core/net/ssl/SSL.java of the component Keystore Handler. The manipulation of the argument DEFAULT KEYSTORE PASSWORD with the input changeit leads to the use of a hard-coded password. The attack may be launched remotely, with a rather high complexity and difficult exploitation. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations As a temporary workaround, consider restricting access to the Keystore Handler component until a patch is available. Update the app immediately to mitigate the risk of unauthorized access. Monitor for signs of compromise.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-11026

Affected Products

Intelligent Apps Freenow App