CVE-2024-7295

In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:telerik_report_server:*:*:*:*:*:*:*:*

History

18 Nov 2024, 17:41

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 6.2
CPE cpe:2.3:a:progress:telerik_report_server:*:*:*:*:*:*:*:*
First Time Progress
Progress telerik Report Server
Summary
  • (es) En las versiones de In Progress® Telerik® Report Server anteriores al cuarto trimestre de 2024 (10.3.24.1112), el cifrado de datos de activos locales utilizaba un algoritmo más antiguo que puede permitir que un actor sofisticado descifre esta información.
References () https://docs.telerik.com/report-server/knowledge-base/encryption-weakness-cve-2024-7295 - () https://docs.telerik.com/report-server/knowledge-base/encryption-weakness-cve-2024-7295 - Vendor Advisory

13 Nov 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-13 16:15

Updated : 2024-11-18 17:41


NVD link : CVE-2024-7295

Mitre link : CVE-2024-7295

CVE.ORG link : CVE-2024-7295


JSON object : View

Products Affected

progress

  • telerik_report_server
CWE
CWE-798

Use of Hard-coded Credentials