PT-2024-38899 · Fortra · Robot Schedule Enterprise Agent

Published

2024-10-09

·

Updated

2024-10-17

·

CVE-2024-8264

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Fortra's Robot Schedule Enterprise Agent versions prior to 3.05
Description: The issue concerns the writing of FTP username and password information to the agent log file when detailed logging is enabled. This affects the security of the system by potentially exposing sensitive credentials.
Recommendations: For versions prior to 3.05, update to version 3.05 or later to resolve the issue. As a temporary workaround, consider disabling detailed logging until the update is applied. Restrict access to the agent log file to minimize the risk of credential exposure.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-8264

Affected Products

Robot Schedule Enterprise Agent