CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by HTTPS.
History

Thu, 17 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Schneider-electric
Schneider-electric data Center Expert
CPEs cpe:2.3:a:schneider-electric:data_center_expert:*:*:*:*:*:*:*:*
Vendors & Products Schneider-electric
Schneider-electric data Center Expert
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Description CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by HTTPS.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published: 2024-10-11T13:55:30.353Z

Updated: 2024-10-17T19:54:14.904Z

Reserved: 2024-09-06T16:49:22.117Z

Link: CVE-2024-8530

cve-icon Vulnrichment

Updated: 2024-10-11T16:40:37.784Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-11T14:15:05.970

Modified: 2024-10-15T12:58:51.050

Link: CVE-2024-8530

cve-icon Redhat

No data.