CVE-2024-24272: High severity itop dualsafe password manager & digital vault vulnerability
An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24272?
CVE-2024-24272 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2024-24272?
To fix CVE-2024-24272, upgrade iTop DualSafe Password Manager & Digital Vault to version 1.4.24 or later.
What types of sensitive information are affected by CVE-2024-24272?
CVE-2024-24272 allows for the leakage of credentials in plaintext, which can lead to unauthorized access.
Who can exploit CVE-2024-24272?
A local attacker with access to the system can exploit CVE-2024-24272 to obtain leaked credentials.
What versions of iTop DualSafe Password Manager & Digital Vault are affected by CVE-2024-24272?
CVE-2024-24272 affects all versions of iTop DualSafe Password Manager & Digital Vault prior to 1.4.24.