The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely stored, which could be abused to possibly change or remove the server configuration.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Eaton
Eaton foreseer Electrical Power Monitoring System |
|
CPEs | cpe:2.3:a:eaton:foreseer_electrical_power_monitoring_system:*:*:*:*:*:*:*:* | |
Vendors & Products |
Eaton
Eaton foreseer Electrical Power Monitoring System |
|
Metrics |
ssvc
|
Fri, 13 Sep 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely stored, which could be abused to possibly change or remove the server configuration. | |
Weaknesses | CWE-522 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Eaton
Published: 2024-09-13T16:48:12.280Z
Updated: 2024-09-13T17:34:40.354Z
Reserved: 2024-04-03T11:17:01.662Z
Link: CVE-2024-31415
Vulnrichment
Updated: 2024-09-13T17:34:35.706Z
NVD
Status : Analyzed
Published: 2024-09-13T17:15:11.907
Modified: 2024-09-19T18:50:27.827
Link: CVE-2024-31415
Redhat
No data.