Description

No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior.

INFO

Published Date :

2024-09-12T00:00:00.000Z

Last Modified :

2024-10-31T19:43:08.722Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-40457 vulnerability.

Vendors Products
No-ip
  • Duc

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact