CVE-2024-3543

Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:loadmaster:*:*:*:*:ltsf:*:*:*
cpe:2.3:a:progress:loadmaster:*:*:*:*:ga:*:*:*
cpe:2.3:a:progress:loadmaster:7.2.48.11:*:*:*:lts:*:*:*

History

10 Feb 2025, 15:16

Type Values Removed Values Added
References () https://kemptechnologies.com/ - () https://kemptechnologies.com/ - Product
References () https://support.kemptechnologies.com/hc/en-us/articles/25724813518605-ECS-Connection-Manager-Security-Vulnerabilities-CVE-2024-3544-and-CVE-2024-3543 - () https://support.kemptechnologies.com/hc/en-us/articles/25724813518605-ECS-Connection-Manager-Security-Vulnerabilities-CVE-2024-3544-and-CVE-2024-3543 - Product
CWE CWE-522
First Time Progress
Progress loadmaster
CPE cpe:2.3:a:progress:loadmaster:*:*:*:*:ltsf:*:*:*
cpe:2.3:a:progress:loadmaster:7.2.48.11:*:*:*:lts:*:*:*
cpe:2.3:a:progress:loadmaster:*:*:*:*:ga:*:*:*

21 Nov 2024, 09:29

Type Values Removed Values Added
Summary
  • (es) El uso de un algoritmo de cifrado de contraseña reversible permite a los atacantes descifrar contraseñas. El atacante puede descifrar fácilmente la información confidencial y las credenciales robadas pueden usarse para acciones arbitrarias que corrompan el sistema.
References () https://kemptechnologies.com/ - () https://kemptechnologies.com/ -
References () https://support.kemptechnologies.com/hc/en-us/articles/25724813518605-ECS-Connection-Manager-Security-Vulnerabilities-CVE-2024-3544-and-CVE-2024-3543 - () https://support.kemptechnologies.com/hc/en-us/articles/25724813518605-ECS-Connection-Manager-Security-Vulnerabilities-CVE-2024-3544-and-CVE-2024-3543 -

02 May 2024, 15:15

Type Values Removed Values Added
Summary (en) Use of reversible password encryption algorithm allows attackers to decrypt passwords.   Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system. (en) Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.

02 May 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-02 14:15

Updated : 2025-02-10 15:16


NVD link : CVE-2024-3543

Mitre link : CVE-2024-3543

CVE.ORG link : CVE-2024-3543


JSON object : View

Products Affected

progress

  • loadmaster
CWE
CWE-257

Storing Passwords in a Recoverable Format

CWE-522

Insufficiently Protected Credentials