First published: Wed Oct 09 2024(Updated: )
Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.
Credit: df4dee71-de3a-4139-9588-11b62fe6c0ff
Affected Software | Affected Version | How to fix |
---|---|---|
Fortra Robot Schedule | >=1.24<3.05 |
Disable detailed logging for FTP and remove any sensitive log files. After upgrading to Robot Schedule Enterprise 3.05, detailed logging for FTP can be re-enabled as the username and password will no longer be written to the agent log.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8264 is considered a moderate severity vulnerability due to the exposure of sensitive FTP credentials in log files.
To mitigate CVE-2024-8264, upgrade to Fortra Robot Schedule Enterprise Agent version 3.05 or later.
CVE-2024-8264 can potentially allow unauthorized access to systems if FTP credentials are exposed in the log files.
CVE-2024-8264 affects Fortra Robot Schedule Enterprise versions prior to 3.05.
Using detailed logging with CVE-2024-8264 is not safe unless mitigations are in place to prevent sensitive information exposure.