CVE-2024-39888

HIGH

Mendix Encryption <10.0.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in Mendix Encryption (All versions >= V10.0.0 < V10.0.2). Affected versions of the module define a specific hard-coded default value for the EncryptionKey constant, which is used in projects where no individual EncryptionKey was specified. This could allow to an attacker to decrypt any encrypted project data, as the default encryption key can be considered compromised.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-547
Status published
Products (1)
Siemens/Mendix Encryption V10.0.0 - V10.0.2
Published Jul 09, 2024
Tracked Since Feb 18, 2026