CVE-2024-42027
MEDIUMDescription
The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time and resources.
Is your site exposed to CVE-2024-42027?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2024-42027? +
How severe is CVE-2024-42027? +
How do I check if I'm vulnerable to CVE-2024-42027? +
Related Vulnerabilities
Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a …
Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When used, they …
The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as root using …
ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 …
Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs …
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to …