Review reviewCritical
CVE-2024-22902
vinchin backup and recovery
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
- CVSS
- 9.8
- EPSS
- 1.07% 61.5% percentile
- CISA KEV
- Not listed
- Published
- 2024.02.02
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
The CVSS severity warrants an early asset and exposure review.
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
Confirm exposure before applying a vendor-supported change.
Confirm that vinchin backup and recovery and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.