2N Access Commander Hardcoded AES Passphrase Exposure Vulnerability

Vulnerability

A vulnerability exists in 2N Access Commander versions through 1.14, allowing an attacker with Admin access to read a hardcoded AES passphrase. This passphrase could be used to decrypt certain data in backup files. 2N has released version 3.3 of Access Commander, which addresses this vulnerability. Users are advised to update to the latest version.

Impact

Exploitation of this vulnerability could lead to unauthorized access to decrypted data from backup files, potentially exposing sensitive information.

Remediation

Users are recommended to update 2N Access Commander to version 3.3 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.