OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote attackers with regular privileges to obtain accounts and password hashes of other users.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Sep 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Syscomgo
Syscomgo omflow |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:syscomgo:omflow:*:*:*:*:*:*:*:* | |
Vendors & Products |
Syscomgo
Syscomgo omflow |
Mon, 16 Sep 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 16 Sep 2024 06:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote attackers with regular privileges to obtain accounts and password hashes of other users. | |
Title | The SYSCOM Group OMFLOW - Improper Authorization for Data Query Function | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-09-16T05:56:22.825Z
Updated: 2024-09-16T13:05:35.370Z
Reserved: 2024-09-13T09:43:50.369Z
Link: CVE-2024-8780
Vulnrichment
Updated: 2024-09-16T13:05:28.399Z
NVD
Status : Analyzed
Published: 2024-09-16T06:15:12.360
Modified: 2024-09-20T14:35:20.250
Link: CVE-2024-8780
Redhat
No data.