CVE-2024-7293: Password policy for new users is not strong enough
Published Oct 9, 2024
·Updated
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
Affected Software
1 affected component
Progress Telerik Reporting<10.2.24.806
Event History
Oct 9, 2024
CVE Published
via MITRE·02:43 PM
Data Sourced
via MITRE·02:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7293?
CVE-2024-7293 has a high severity rating due to its potential for password brute forcing attacks.
2
How do I fix CVE-2024-7293?
To fix CVE-2024-7293, upgrade to In Progress® Telerik® Report Server version 2024 Q3 (10.2.24.806) or later.
3
What software is affected by CVE-2024-7293?
CVE-2024-7293 affects In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806).
4
What type of attack is possible due to CVE-2024-7293?
CVE-2024-7293 enables attackers to perform password brute forcing attacks due to weak password requirements.
5
What are the implications of exploiting CVE-2024-7293?
Exploiting CVE-2024-7293 could lead to unauthorized access to sensitive data and functionalities within the Telerik® Report Server.