← back
CVE-2024-3182

CVE-2024-3182

CVSS 6.5 MEDIUMEPSS 0.2%CWE-200
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
15 May 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected products
TIBCO · Hawk

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →