CVE-2024-9620

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Oct 10, 2024
CWE ID 319

Summary

CVE-2024-9620 is a vulnerability identified in the Event-Driven Automation (EDA) component of the Ansible Automation Platform (AAP), which fails to encrypt sensitive information. This issue affects several products including s9Tulv, s9Tulu, ns62NJ, ns62NH, and nsd3K4. Exploitation of this flaw could allow an attacker with network access to intercept plaintext data transmitted between EDA and AAP or read plaintext data stored in their databases if they have system access. The vulnerability is rated with a medium-severity base score of 5.3 and has a low confidentiality impact. Remediation involves implementing encryption for sensitive data transmissions to mitigate potential risks associated with unauthorized data exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share