CVE-2024-5275: Hard-coded password in FileCatalyst Direct 3.8.10 Build 138 TransferAgent (and earlier) and FileCatalyst Workflow 5.1.6 Build 130 (and earlier)
A hard-coded password in the FileCatalyst TransferAgent can be found which can be used to unlock the keystore from which contents may be read out, for example, the private key for certificates. Exploit of this vulnerability could lead to a machine-in-the-middle (MiTM) attack against users of the agent. This issue affects all versions of FileCatalyst Direct from 3.8.10 Build 138 and earlier and all versions of FileCatalyst Workflow from 5.1.6 Build 130 and earlier.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FileCatalyst Directto a version that resolves this vulnerability.Fixed in 3.8.10 build 144 (or higher) - Upgrade
Upgrade
FileCatalyst Workflowto a version that resolves this vulnerability.Fixed in 5.1.6 build 133 (or later) - Configuration
If using the FileCatalyst TransferAgent remotely (e.g., as a remote-controlled node accepting REST calls), update REST calls to use "http" instead of "https".
FileCatalyst TransferAgent (remote use via REST calls) REST calls scheme = http - Configuration
If "https" is still required, create a new SSL key and add it to the agent keystore.
FileCatalyst TransferAgent keystore Keystore SSL key = new SSL key
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5275?
CVE-2024-5275 is considered a high-severity vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2024-5275?
To mitigate CVE-2024-5275, users should update the FileCatalyst Direct to version 3.8.10 Build 139 or later and FileCatalyst Workflow to version 5.1.6 Build 131 or later.
What software is affected by CVE-2024-5275?
CVE-2024-5275 affects Fortra FileCatalyst Direct versions up to 3.8.10 Build 138 and FileCatalyst Workflow versions up to 5.1.6 Build 130.
What kind of attack can exploit CVE-2024-5275?
Exploitation of CVE-2024-5275 may facilitate machine-in-the-middle (MiTM) attacks.
What is the primary risk associated with CVE-2024-5275?
The primary risk associated with CVE-2024-5275 is the potential exposure of sensitive data, including private keys and other secure contents.