Weak Password Recovery Vulnerability in TDuckCloud TDuckPro
CVE-2024-8692
Key Information:
- Vendor
- Tduckcloud
- Status
- Tduckpro
- Vendor
- CVE Published:
- 11 September 2024
Badges
Summary
A significant vulnerability has been identified in TDuckCloud's TDuckPro, specifically versions up to 6.3. This flaw relates to the application's password recovery feature, which has been found to be inadequately secured. As a result, attackers can exploit this weakness remotely, potentially allowing unauthorized individuals to reset user passwords without proper authorization. Despite early notifications, TDuckCloud has yet to address this critical issue, leaving users exposed to possible security breaches. It is crucial for organizations using TDuckPro to assess their security posture and apply any available mitigations against this vulnerability.
Affected Version(s)
TDuckPro 6.0
TDuckPro 6.1
TDuckPro 6.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved