Aqua Vulnerability Database
Get Demo
Vulnerabilities
Misconfiguration
Runtime Security
Compliance
CVE Vulnerabilities
CVE-2024-22901
Published:
Feb 02, 2024
| Modified:
Feb 07, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
Additional information
NVD
https://nvd.nist.gov/vuln/detail/CVE-2024-22901
CWE
https://cwe.mitre.org/data/definitions/NVD-Other.html
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
Affected Software
Name
Vendor
Start Version
End Version
Vinchin_backup_and_recovery
Vinchin
*
7.2 (including)
References
http://vinchin.com
https://blog.leakix.net/2024/01/vinchin-backup-rce-chain/
https://seclists.org/fulldisclosure/2024/Jan/30
Aqua Container Security