CVE-2024-42027
MEDIUMDescription
The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time and resources.
Is your site exposed to CVE-2024-42027?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2024-42027? +
How severe is CVE-2024-42027? +
How do I check if I'm vulnerable to CVE-2024-42027? +
Related Vulnerabilities
In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can …
Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When used, they …
The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as root using …
Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local …
Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. …