CVE-2024-8692
MEDIUMTDuckCloud TDuckPro <6.3 - Weak Password Recovery
Title source: llmDescription
A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scores
CVSS v3
5.3
EPSS
0.0013
EPSS Percentile
32.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-640
Status
published
Affected Products (1)
tduckcloud/tduckpro
< 6.3
Timeline
Published
Sep 11, 2024
Tracked Since
Feb 18, 2026