Impact
This vulnerability results from credentials that are insufficiently protected within Azure CycleCloud. An attacker who already has authorized access can exploit this weakness to retrieve sensitive information over the network, potentially aiding further compromise or data exfiltration. The flaw is associated with CWE-522, indicating that credential information may be exposed during normal operation.
Affected Systems
Microsoft Azure CycleCloud version 8.9.2 is known to be affected. No other product versions were listed in the CNA data, so the scope is limited to this specific release.
Risk and Exploitability
The CVSS score of 7.7 classifies the vulnerability as high. EPSS data is not available, so the exact likelihood of exploitation cannot be quantified, but the vulnerability is not currently listed in CISA’s KEV catalog, suggesting it has not yet been widely employed in the wild. Since the attack vector requires an attacker who has already bypassed initial controls, the risk is concentrated on systems where privileged or authorized accounts exist. Remediation is recommended before the vulnerability becomes a vector for broader attacks.
OpenCVE Enrichment