CVE Vulnerabilities

CVE-2024-23583

Insufficiently Protected Credentials

Published: May 17, 2024 | Modified: Jan 08, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Bigfix_platformHcltech9.5 (including)9.5.25 (excluding)
Bigfix_platformHcltech10 (including)10.0.12 (excluding)
Bigfix_platformHcltech11.0.1 (including)11.0.1 (including)

Potential Mitigations

References