PT-2024-25508 · Unknown · Ci-Out-Of-Office Manager

Jürgen Zöller

·

Published

2024-05-28

·

Updated

2024-08-01

·

CVE-2024-33849

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CI-Out-of-Office Manager versions through 6.0.0.77
Description The issue concerns the use of a hard-coded cryptographic key in the software. This could potentially allow unauthorized access or decryption of sensitive data.
Recommendations For versions through 6.0.0.77, consider updating to a version that does not use a hard-coded cryptographic key, if available. As a temporary workaround, restrict access to sensitive data handled by the CI-Out-of-Office Manager to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-33849

Affected Products

Ci-Out-Of-Office Manager