PT-2025-5859 · 2N · 2N Access Commander

Jylsec

·

Published

2025-02-06

·

Updated

2025-02-21

·

CVE-2024-47256

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions 2N Access Commander versions 1.14 and older
Description The issue allows an attacker with Admin access privileges to read a hardcoded AES passphrase, which can be used to decrypt certain data within backup files.
Recommendations For 2N Access Commander versions 1.14 and older, consider restricting access to the backup files and the hardcoded AES passphrase until a patch is available. As a temporary workaround, limit the use of Admin access privileges to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-47256

Affected Products

2N Access Commander