CVE-2024-38341
MEDIUMDescription
IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Is your site exposed to CVE-2024-38341?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | sterling_secure_proxy |
| ibm | sterling_secure_proxy |
| ibm | sterling_secure_proxy |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-38341? +
How severe is CVE-2024-38341? +
What products are affected by CVE-2024-38341? +
How do I check if I'm vulnerable to CVE-2024-38341? +
Related Vulnerabilities
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically …
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with …
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes, making …
free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API format. In versions up …
R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to …
Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographically …