CVE-2024-7346 is a medium-severity vulnerability affecting Progress OpenEdge products, where the use of default OpenEdge certificates bypasses hostname validation during TLS handshakes. This allows for potential compromise of confidentiality and integrity with low impact. While the vulnerability has a CVSS score of 4.8, it has a very low EPSS score and no known public exploits, Metasploit modules, or Nuclei templates, indicating a low current exploitation risk and minimal community discussion or media coverage. Organizations are advised to replace default certificates with CA-signed certificates to ensure proper hostname validation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.7.19CPE matchmatch criteria | cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:* | ||
>= 12.0, <= 12.2.14CPE matchmatch criteria | cpe:2.3:a:progress:openedge:*:*:*:*:lts:*:*:* | ||
>= 11.7.0, <= 11.7.19CPE match | cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:* | ||
>= 12.2.0, <= 12.2.14CPE match | cpe:2.3:a:progress:openedge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.