IM
IronMonkey Threat Research

CVE-2024-1531 HIGH

Published: 2024-03-27 | Last Modified: 2026-04-15 | Status: Deferred

Description

A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content in the RTU500 system log, if an authorized user uploads a specially crafted stb-language file.

Additional Descriptions (1)

Existe una vulnerabilidad en el manejo de archivos en lenguaje stb que afecta a las versiones de productos de la serie RTU500 que se enumeran a continuación. Un actor malintencionado podría imprimir contenido de memoria aleatorio en el registro del sistema RTU500, si un usuario autorizado carga un archivo en lenguaje stb especialmente manipulado.

CVSS Metrics

Base Score: 8.2 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactLOW
Integrity ImpactLOW
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 2.3

Impact Score: 5.3

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-434
Notification
Message here