PT-2024-4732 · Bas Ip · Bas-Ip Av-01D+11

Drievlad

·

Published

2024-06-21

·

Updated

2024-06-24

·

CVE-2024-37654

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, AV-04FD, AV-04SD, AV-05FD, AV-05SD, AA-07BD, AA-07BDI, BA-04BD, BA-04MD, BA-08BD, BA-08MD, BA-12BD, BA-12MD, CR-02BD versions prior to 3.9.2
Description: The issue allows a remote attacker to obtain sensitive information via a crafted HTTP GET request. It is related to the storage of credentials in configuration files, which can be exploited by sending a specially formed HTTP request to reveal protected information.
Recommendations: For versions prior to 3.9.2, update to version 3.9.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface until a patch is available. Avoid using the web interface for sensitive operations until the issue is resolved.

Fix

Insecure Storage of Sensitive Information

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05251
CVE-2024-37654

Affected Products

Bas-Ip Aa-07Bd
Bas-Ip Av-01Bd
Bas-Ip Av-01D
Bas-Ip Av-02D
Bas-Ip Av-03Bd
Bas-Ip Av-04Afd
Bas-Ip Av-04Asd
Bas-Ip Av-05Fd
Bas-Ip Ba-04Bd
Bas-Ip Ba-08Bd
Bas-Ip Ba-12Bd
Bas-Ip Cr-02Bd