First published: Thu May 23 2024(Updated: )
Network Transfer with AES KHT in Thales Luna EFT 2.1 and above allows a user with administrative console access to access backups taken via offline analysis
Credit: psirt@thalesgroup.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thales Luna Eft | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-5264 is considered high due to the risk of unauthorized access to sensitive backups.
To fix CVE-2024-5264, ensure that proper access controls are enforced for the administrative console in Thales Luna EFT.
CVE-2024-5264 affects Thales Luna EFT version 2.1 and above.
Users with administrative console access can exploit CVE-2024-5264 to access backups during offline analysis.
The potential consequences of CVE-2024-5264 include unauthorized access to sensitive data and compromised backup security.