Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-49053 Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.
Fixes

Solution

Disable detailed logging for FTP and remove any sensitive log files. After upgrading to Robot Schedule Enterprise 3.05, detailed logging for FTP can be re-enabled as the username and password will no longer be written to the agent log.


Workaround

Disable detailed logging for FTP if it was previously enabled and remove any sensitive log files. NOTE: if detailed logging is not enabled, there is no exposure to this issue.

History

Thu, 17 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Fortra robot Schedule
CPEs cpe:2.3:a:fortra:robot_schedule:*:*:*:*:enterprise:*:*:*
Vendors & Products Fortra robot Schedule

Fri, 11 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Fortra
Fortra robot Schedule Enterprise
CPEs cpe:2.3:a:fortra:robot_schedule_enterprise:*:*:*:*:*:*:*:*
Vendors & Products Fortra
Fortra robot Schedule Enterprise
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Oct 2024 23:00:00 +0000

Type Values Removed Values Added
Description Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.
Title Sensitive information in agent log file when detailed logging is enabled with Robot Schedule Enterprise prior to version 3.05
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2024-10-10T20:16:18.755Z

Reserved: 2024-08-28T15:44:42.812Z

Link: CVE-2024-8264

cve-icon Vulnrichment

Updated: 2024-10-10T20:16:05.595Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-09T23:15:11.093

Modified: 2024-10-17T14:06:39.420

Link: CVE-2024-8264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.