CVE-2022-36617

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
09/09/2022
Last modified:
14/09/2022

Description

Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:haystacksoftware:arq_backup:*:*:*:*:*:*:*:* 7.19.5.0 (including)