Description
Use of reversible password encryption algorithm allows attackers to decrypt passwords. Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.
Scores
CVSS v3
6.4
EPSS
0.0013
EPSS Percentile
32.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-522
CWE-257
Status
published
Products (3)
progress/loadmaster
7.2.48.11
progress/loadmaster
7.2.49.0 - 7.2.54.10
progress/loadmaster
7.2.55.0 - 7.2.59.4
Published
May 02, 2024
Tracked Since
Feb 18, 2026