CVE Vulnerabilities

CVE-2024-40457

Cleartext Storage of Sensitive Information

Published: Sep 12, 2024 | Modified: Oct 31, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendors position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Potential Mitigations

References