CVE-2024-28275
Last modified
CVE-2024-28275 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive information, including users' credentials and password change requests.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive information, including users' credentials and password change requests.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-28275?
How severe is CVE-2024-28275?
How do I fix CVE-2024-28275?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-28255OpenMetadata is a unified platform for discovery, observabil…9.8
- CVE-2024-2826A vulnerability classified as problematic was found in laker…8.8
- CVE-2024-28265IBOS v4.5.5 has an arbitrary file deletion vulnerability via…9.1
- CVE-2024-28269ReCrystallize Server 5.10.0.0 allows administrators to uploa…7.2
- CVE-2024-2827A vulnerability, which was classified as critical, has been …8.8
- CVE-2024-28270An issue discovered in web-flash v3.0 allows attackers to re…8.1
- CVE-2024-28276Sourcecodester School Task Manager 1.0 is vulnerable to Cros…6.1
- CVE-2024-28277In Sourcecodester School Task Manager v1.0, a vulnerability …6.1
- CVE-2024-28279Code-projects Computer Book Store 1.0 is vulnerable to SQL I…7.3
- CVE-2024-2828A vulnerability, which was classified as critical, was found…8.8
- CVE-2024-28283There is stack-based buffer overflow vulnerability in pc_cha…6.7
- CVE-2024-28285A Fault Injection vulnerability in the SymmetricDecrypt func…9.8
Are you affected by CVE-2024-28275?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
