Weak Encoding for Password
CVE-2024-45273
Summary
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
- LOW
- LOCAL
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-261 - Weak Encoding for Password
Obscuring a password with a trivial encoding does not protect the password.
References
Advisory Timeline
- Published