CVE-2024-5275: Hard-coded password in FileCatalyst Direct 3.8.10 Build 138 TransferAgent (and earlier) and FileCatalyst Workflow 5.1.6 Build 130 (and earlier)

Published Jun 18, 2024
·
Updated

A hard-coded password in the FileCatalyst TransferAgent can be found which can be used to unlock the keystore from which contents may be read out, for example, the private key for certificates. Exploit of this vulnerability could lead to a machine-in-the-middle (MiTM) attack against users of the agent. This issue affects all versions of FileCatalyst Direct from 3.8.10 Build 138 and earlier and all versions of FileCatalyst Workflow from 5.1.6 Build 130 and earlier.

Affected Software

2 affected components
FileCatalyst Direct<3.8.10 Build 138
FileCatalyst Workflow<5.1.6 Build 130

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FileCatalyst Direct to a version that resolves this vulnerability.

    Fixed in 3.8.10 build 144 (or higher)
  2. Upgrade

    Upgrade FileCatalyst Workflow to a version that resolves this vulnerability.

    Fixed in 5.1.6 build 133 (or later)
  3. Configuration

    If using the FileCatalyst TransferAgent remotely (e.g., as a remote-controlled node accepting REST calls), update REST calls to use "http" instead of "https".

    FileCatalyst TransferAgent (remote use via REST calls) REST calls scheme = http
  4. Configuration

    If "https" is still required, create a new SSL key and add it to the agent keystore.

    FileCatalyst TransferAgent keystore Keystore SSL key = new SSL key

Event History

Jun 18, 2024
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-5275?

CVE-2024-5275 is considered a high-severity vulnerability due to the potential for unauthorized access to sensitive information.

2

How do I fix CVE-2024-5275?

To mitigate CVE-2024-5275, users should update the FileCatalyst Direct to version 3.8.10 Build 139 or later and FileCatalyst Workflow to version 5.1.6 Build 131 or later.

3

What software is affected by CVE-2024-5275?

CVE-2024-5275 affects Fortra FileCatalyst Direct versions up to 3.8.10 Build 138 and FileCatalyst Workflow versions up to 5.1.6 Build 130.

4

What kind of attack can exploit CVE-2024-5275?

Exploitation of CVE-2024-5275 may facilitate machine-in-the-middle (MiTM) attacks.

5

What is the primary risk associated with CVE-2024-5275?

The primary risk associated with CVE-2024-5275 is the potential exposure of sensitive data, including private keys and other secure contents.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203