CVE-2022-36617
MEDIUMHaystacksoftware Arq Backup - Insufficiently Protected Credentials
Title source: ruleDescription
Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.
Scores
CVSS v3
4.9
EPSS
0.0024
EPSS Percentile
47.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
Status
published
Affected Products (1)
haystacksoftware/arq_backup
< 7.19.5.0
Timeline
Published
Sep 09, 2022
Tracked Since
Feb 18, 2026