OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote attackers with regular privileges to obtain accounts and password hashes of other users.
History

Fri, 20 Sep 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Syscomgo
Syscomgo omflow
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:syscomgo:omflow:*:*:*:*:*:*:*:*
Vendors & Products Syscomgo
Syscomgo omflow

Mon, 16 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Sep 2024 06:00:00 +0000

Type Values Removed Values Added
Description OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote attackers with regular privileges to obtain accounts and password hashes of other users.
Title The SYSCOM Group OMFLOW - Improper Authorization for Data Query Function
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-09-16T05:56:22.825Z

Updated: 2024-09-16T13:05:35.370Z

Reserved: 2024-09-13T09:43:50.369Z

Link: CVE-2024-8780

cve-icon Vulnrichment

Updated: 2024-09-16T13:05:28.399Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-16T06:15:12.360

Modified: 2024-09-20T14:35:20.250

Link: CVE-2024-8780

cve-icon Redhat

No data.