PT-2024-28835 · Cybele · Thinfinity Workspace

Published

2024-11-13

·

Updated

2024-11-25

·

CVE-2024-40410

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cybele Software Thinfinity Workspace versions prior to 7.0.2.113
Description The issue concerns a hardcoded cryptographic key used for encryption. This key is embedded in the software, potentially allowing unauthorized access or exploitation. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions prior to 7.0.2.113, upgrade to version 7.0.2.113 or later to mitigate the risks associated with the hardcoded cryptographic key.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-40410

Affected Products

Thinfinity Workspace