CVE-2022-36617

MEDIUM

Haystacksoftware Arq Backup - Insufficiently Protected Credentials

Title source: rule

Description

Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.

Scores

CVSS v3 4.9
EPSS 0.0024
EPSS Percentile 47.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (1)

haystacksoftware/arq_backup < 7.19.5.0

Timeline

Published Sep 09, 2022
Tracked Since Feb 18, 2026