CVE-2024-52334
Awaiting Analysis Awaiting Analysis - Queue
Improper Password Encryption in syngo.plaza VB30E Enables Unauthorized Access

Publication date: 2026-02-10

Last updated on: 2026-02-10

Assigner: Siemens AG

Description
A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not encrypt the passwords properly. This could allow an attacker to recover the original passwords and might gain unauthorized access.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-10
Last Modified
2026-02-10
Generated
2026-06-16
AI Q&A
2026-02-10
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
siemens syngo.plaza to VB30E_HF07 (exc)
siemens syngo.plaza_vb30e to VB30E_HF07 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-261 Obscuring a password with a trivial encoding does not protect the password.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Executive Summary

This vulnerability exists in the syngo.plaza VB30E application (all versions before VB30E_HF07). The issue is that the application does not properly encrypt passwords.

Because of this improper encryption, an attacker could potentially recover the original passwords.

This could allow unauthorized access to the system or application.

Impact Analysis

The vulnerability could allow an attacker to recover user passwords due to improper encryption.

With recovered passwords, the attacker might gain unauthorized access to the affected system or application.

This unauthorized access could lead to potential data exposure or misuse of system resources.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-52334. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart