CVE-2024-39888
A vulnerability has been identified in Mendix Encryption (All versions >= V10.0.0 < V10.0.2). Affected versions of the module define a specific hard-coded default value for the EncryptionKey constant, which is used in projects where no individual EncryptionKey was specified. This could allow to an attacker to decrypt any encrypted project data, as the default encryption key can be considered compromised.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.24%
- CWE
- CWE-547
- Published
- 2024-07-09
- Last modified
- 2026-03-13
Affected products
- Siemens Mendix Encryption
Weakness type
Related vulnerabilities
- CVE-2026-28256 — Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
- CVE-2025-49151 — Use of Hard-coded, Security-relevant Constants in MICROSENS NMP Web+
- CVE-2025-23253 — NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an...
- CVE-2025-30206 — Dpanel's hard-coded JWT secret leads to remote code execution
- CVE-2025-2081 — Use of Hard-Coded, Security-Relevant Constants
- CVE-2025-2079 — Use of Hard-Coded, Security-Relevant Constants in Optigo Networks Visual BACnet Capture Tool / Optigo Visual Networks Capture Tool
- CVE-2024-41885 — Hardcoding sensitive information
- CVE-2024-32021 — Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory