CVE-2024-34113
ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation that compromises the confidentiality of password data. An attacker could exploit this weakness to decrypt or guess passwords, potentially gaining unauthorized access to protected resources. Exploitation of this issue does not require user interaction.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.34%
- CWE
- CWE-261
- Published
- 2024-06-13
- Last modified
- 2026-03-13
Affected products
- Adobe ColdFusion
Weakness type
Related vulnerabilities
- CVE-2026-63424 — During an internal security assessment, an improperly protected key was discovered in Lenovo Dock...
- CVE-2026-67596 — CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg
- CVE-2026-53692 — Weak hashing algorithm in Redeight CMS
- CVE-2026-40639 — Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated...
- CVE-2026-25607 — Weak password encoding in STER
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2026-0809 — Weak KSeF token encoding in Streamsoft Prestiż
- CVE-2024-52334 — A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected...