CVE-2024-47256 – 2N Access Commander AES Passphrase Information Disclosure Vulnerability

The following table lists the changes that have been made to the
CVE-2024-47256 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 06, 2025

    Action Type Old Value New Value
    Added Description Successful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to read hardcoded AES passphrase, which may be used for decryption of certain data within backup files of 2N Access Commander version 1.14 and older.
    Added CVSS V3.1 AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
    Added CWE CWE-321
    Added Reference https://www.2n.com/en-GB/download/cve_2024_47256_acom_3_3_v1pdf
Share the Post:

Related Posts