IM
IronMonkey Threat Research

CVE-2024-7940 CRITICAL

Published: 2024-08-27 | Last Modified: 2024-08-28 | Status: Analyzed

Description

The product exposes a service that is intended for local only to all network interfaces without any authentication.

Additional Descriptions (1)

El producto expone un servicio destinado únicamente al nivel local para todas las interfaces de red sin ninguna autenticación.

CVSS Metrics

Base Score: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 5.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-306
[email protected] Primary
en CWE-306

Affected Products

Vendor Product Version Update Type
hitachienergy microscada_x_sys600 * <built-in method update of dict object at 0x72a9ccd2bdc0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:*
Notification
Message here