IM
IronMonkey Threat Research

CVE-2024-41156 LOW

Published: 2024-10-29 | Last Modified: 2024-12-05 | Status: Analyzed

Description

Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users with higher privilege of write access.

Additional Descriptions (1)

Los archivos de perfil de las radios de la serie TRO600 se extraen en formato de texto plano y en formato de archivo cifrado. Los archivos de perfil proporcionan a los posibles atacantes información valiosa sobre la configuración de la red Tropos. Los perfiles solo pueden ser exportados por usuarios autenticados con acceso de escritura.

CVSS Metrics

Base Score: 2.7 (LOW)

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactLOW
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 1.2

Impact Score: 1.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-212
[email protected] Primary
en CWE-212

Affected Products

Vendor Product Version Update Type
hitachienergy tro610_firmware * <built-in method update of dict object at 0x72a9b0c990c0> Operating System
hitachienergy tro620_firmware * <built-in method update of dict object at 0x72a9cc557440> Operating System
hitachienergy tro670_firmware * <built-in method update of dict object at 0x72a9cd0c2b80> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:hitachienergy:tro610_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:hitachienergy:tro610:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:hitachienergy:tro620_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:hitachienergy:tro620:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:hitachienergy:tro670_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:hitachienergy:tro670:-:*:*:*:*:*:*:*
Notification
Message here