CVE-2024-51993

CVSS 3.0 Score 3.4 of 10 (low)

Details

Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 312

Summary

CVE-2024-51993 is a vulnerability affecting the Combodo iTop IT Service Management tool. If an attacker gains access to a backup file or the database, they can read some user passwords that are stored in plaintext. Users who have not yet upgraded to version 3.2.0 are advised to do so as soon as possible to mitigate this risk. Alternatively, users cannot upgrade can encrypt their backups independently of the iTop application to protect their passwords. This issue is identified as N°7631 and involves a lack of sufficient data sanitization in the software's parameter handling.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share