« Volver al listado

CVE-2024-3543

Estado: AnalizadaAlta (7.5)—

Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-3543",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-3543",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-02T15:51:54.344919Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@progress.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.4,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@progress.com",
      "affectedData": [
        {
          "vendor": "Progress Software Corporation",
          "product": "LoadMaster",
          "versions": [
            {
              "status": "affected",
              "version": "LoadMaster 7.2.55.0 (GA)",
              "lessThan": "7.2.59.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "LoadMaster 7.2.49.0 (LTSF)",
              "lessThan": "7.2.54.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "LoadMaster 7.2.48.11 (LTS)",
              "lessThan": "7.2.48.12",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:kemptechnologies:loadmaster:7.2.48.11\\(lts\\):*:*:*:*:*:*:*"
          ],
          "vendor": "kemptechnologies",
          "product": "loadmaster",
          "versions": [
            {
              "status": "affected",
              "version": "7.2.48.11\\(lts\\)",
              "lessThan": "7.2.48.12",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:kemptechnologies:loadmaster:7.2.49.0\\(ltsf\\):*:*:*:*:*:*:*"
          ],
          "vendor": "kemptechnologies",
          "product": "loadmaster",
          "versions": [
            {
              "status": "affected",
              "version": "7.2.49.0\\(ltsf\\)",
              "lessThan": "7.2.54.10",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:kemptechnologies:loadmaster:7.2.55.0\\(ga\\):*:*:*:*:*:*:*"
          ],
          "vendor": "kemptechnologies",
          "product": "loadmaster",
          "versions": [
            {
              "status": "affected",
              "version": "7.2.55.0\\(ga\\)",
              "lessThan": "7.5.59.4",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-02T14:15:10.573",
  "references": [
    {
      "url": "https://kemptechnologies.com/",
      "tags": [
        "Product"
      ],
      "source": "security@progress.com"
    },
    {
      "url": "https://support.kemptechnologies.com/hc/en-us/articles/25724813518605-ECS-Connection-Manager-Security-Vulnerabilities-CVE-2024-3544-and-CVE-2024-3543",
      "tags": [
        "Product"
      ],
      "source": "security@progress.com"
    },
    {
      "url": "https://kemptechnologies.com/",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.kemptechnologies.com/hc/en-us/articles/25724813518605-ECS-Connection-Manager-Security-Vulnerabilities-CVE-2024-3544-and-CVE-2024-3543",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@progress.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-257"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nUse of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.\n\n"
    },
    {
      "lang": "es",
      "value": "El uso de un algoritmo de cifrado de contraseña reversible permite a los atacantes descifrar contraseñas. El atacante puede descifrar fácilmente la información confidencial y las credenciales robadas pueden usarse para acciones arbitrarias que corrompan el sistema."
    }
  ],
  "lastModified": "2026-06-17T07:44:29.067",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:progress:loadmaster:*:*:*:*:ltsf:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71C25CAF-73A9-4F9A-9914-ABCFB0C9D4BE",
              "versionEndExcluding": "7.2.54.10",
              "versionStartIncluding": "7.2.49.0"
            },
            {
              "criteria": "cpe:2.3:a:progress:loadmaster:*:*:*:*:ga:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "651AEE76-E95B-4E43-86E6-190062B23FE7",
              "versionEndExcluding": "7.2.59.4",
              "versionStartIncluding": "7.2.55.0"
            },
            {
              "criteria": "cpe:2.3:a:progress:loadmaster:7.2.48.11:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FC71B68-F870-4ECF-9655-6E64C7546C96"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@progress.com"
}