CVE-2024-39888 PUBLISHED CVSS 7.5 HIGH

A vulnerability has been identified in Mendix Encryption (All versions >= V10.0.0 < V10.0.2). Affected versions of the module define a specific hard-coded default value for the EncryptionKey constant, which is used in projects where no individual EncryptionKey was specified. This could allow to an attacker to decrypt any encrypted project data, as the default encryption key can be considered compromised.

EPSS 0.19% · 41.2th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.19%
41.2th percentile

Affected Products

VendorProductVersions
siemensmendix_encryptionV10.0.0, V10.0.0, V10.0.0
SiemensMendix EncryptionV10.0.0, V10.0.0, V10.0.0

Timeline

References

Open in Interactive Console →