CVE-2024-32151
MEDIUMProduct with vulnerability - Info Disclosure
Title source: llmDescription
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
References (7)
Scores
CVSS v3
5.9
EPSS
0.0023
EPSS Percentile
45.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-257
Status
draft
Timeline
Published
Nov 26, 2024
Tracked Since
Feb 18, 2026