A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser.
Metrics
Affected Vendors & Products
References
History
Mon, 12 Aug 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Proges
Proges sensor Net Connect Firmware V2 Proges sensor Net Connect V2 |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:h:proges:sensor_net_connect_v2:-:*:*:*:*:*:*:* cpe:2.3:o:proges:sensor_net_connect_firmware_v2:2.24:*:*:*:*:*:*:* |
|
Vendors & Products |
Proges
Proges sensor Net Connect Firmware V2 Proges sensor Net Connect V2 |
MITRE
Status: PUBLISHED
Assigner: Nozomi
Published: 2024-07-31T13:16:57.751Z
Updated: 2024-07-31T14:21:55.581Z
Reserved: 2024-03-29T08:32:14.699Z
Link: CVE-2024-31200
Vulnrichment
Updated: 2024-07-31T14:21:50.973Z
NVD
Status : Analyzed
Published: 2024-07-31T14:15:03.823
Modified: 2024-08-12T18:25:44.547
Link: CVE-2024-31200
Redhat
No data.