Review reviewCritical
CVE-2024-22901
vinchin backup and recovery
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
- CVSS
- 9.8
- EPSS
- 1.10% 62.5% percentile
- CISA KEV
- Not listed
- Published
- 2024.02.02
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
The CVSS severity warrants an early asset and exposure review.
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
Confirm exposure before applying a vendor-supported change.
Confirm that vinchin backup and recovery and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.