CVE-2024-3543

MEDIUM

Reversible Password Encryption - Info Disclosure

Title source: llm

Description

Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.

Scores

CVSS v3 6.4
EPSS 0.0013
EPSS Percentile 32.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-522 CWE-257
Status published

Affected Products (3)

progress/loadmaster < 7.2.54.10
progress/loadmaster < 7.2.59.4
progress/loadmaster

Timeline

Published May 02, 2024
Tracked Since Feb 18, 2026