Encryption Vulnerability in TRCore's DVC Allows Attackers to Restore Original Content
CVE-2024-11308
5.5MEDIUM
Summary
The TRCore DVC software contains a vulnerability that arises from the use of hardcoded encryption keys for file encryption. This flaw enables attackers to utilize the embedded key to decrypt sensitive files, potentially exposing confidential information. Consequently, organizations using affected versions of DVC might face significant risks, including unauthorized access to critical data and subsequent data breaches. It is crucial for users to take immediate action to mitigate this vulnerability by applying security updates or implementing alternative encryption methods to safeguard their data.
Affected Version(s)
DVC 6.0 <= 6.3
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved