An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses as it indicates whether or not the user is present in CIRCUTOR Q-SMT in its firmware version 1.0.4.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-49461 An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses as it indicates whether or not the user is present in CIRCUTOR Q-SMT in its firmware version 1.0.4.
Fixes

Solution

CIRCUTOR Q-SMT, in its firmware version 1.0.5, effectively solved the potential threat. CIRCUTOR made the new version available to its customers privately and strongly recommends them to keep their equipment updated.


Workaround

No workaround given by the vendor.

History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00121}

epss

{'score': 0.00142}


Thu, 26 Sep 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Circutor q-smt
Circutor q-smt Firmware
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:circutor:q-smt:-:*:*:*:*:*:*:*
cpe:2.3:o:circutor:q-smt_firmware:1.0.4:*:*:*:*:*:*:*
Vendors & Products Circutor q-smt
Circutor q-smt Firmware

Wed, 18 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Circutor
Circutor circutor Q Smt
CPEs cpe:2.3:a:circutor:circutor_q_smt:*:*:*:*:*:*:*:*
Vendors & Products Circutor
Circutor circutor Q Smt
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
Description An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses as it indicates whether or not the user is present in CIRCUTOR Q-SMT in its firmware version 1.0.4.
Title Exposure of Private Personal Information to an Unauthorized Actor vulnerability on CIRCUTOR Q-SMT
Weaknesses CWE-359
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-18T15:28:30.964Z

Reserved: 2024-09-16T10:20:32.471Z

Link: CVE-2024-8891

cve-icon Vulnrichment

Updated: 2024-09-18T15:28:25.261Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-18T14:15:20.187

Modified: 2024-09-26T18:50:56.827

Link: CVE-2024-8891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.