This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker in close proximity could exploit this vulnerability by capturing Wi-Fi traffic of Airveda-AP. Successful exploitation of this vulnerability could allow the attacker to cause Evil Twin attack on the targeted system.
History

Tue, 13 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Airveda
Airveda pm2.5 Pm10 Monitor
Airveda pm2.5 Pm10 Monitor Firmware
CPEs cpe:2.3:h:airveda:pm2.5_pm10_monitor:-:*:*:*:*:*:*:*
cpe:2.3:o:airveda:pm2.5_pm10_monitor_firmware:*:*:*:*:*:*:*:*
Vendors & Products Airveda
Airveda pm2.5 Pm10 Monitor
Airveda pm2.5 Pm10 Monitor Firmware
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Fri, 09 Aug 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Aug 2024 10:45:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker in close proximity could exploit this vulnerability by capturing Wi-Fi traffic of Airveda-AP. Successful exploitation of this vulnerability could allow the attacker to cause Evil Twin attack on the targeted system.
Title Information Disclosure Vulnerability in Airveda Air Quality Monitor
Weaknesses CWE-319
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-08-09T10:40:54.953Z

Updated: 2024-08-09T15:14:15.681Z

Reserved: 2024-08-02T10:47:10.549Z

Link: CVE-2024-7408

cve-icon Vulnrichment

Updated: 2024-08-09T15:14:09.446Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-12T13:38:41.777

Modified: 2024-08-13T16:06:08.213

Link: CVE-2024-7408

cve-icon Redhat

No data.