CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of confidentiality and integrity of controllers. To be successful, the attacker needs to inject themself inside the logical network while a valid user uploads or downloads a project file into the controller.
History

Wed, 13 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Schneider-electric
Schneider-electric modicon M340
Schneider-electric modicon Mc80
Schneider-electric modicon Momentum Unity M1e Processor
CPEs cpe:2.3:h:schneider-electric:modicon_m340:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_mc80:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_momentum_unity_m1e_processor:-:*:*:*:*:*:*:*
Vendors & Products Schneider-electric
Schneider-electric modicon M340
Schneider-electric modicon Mc80
Schneider-electric modicon Momentum Unity M1e Processor
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 Nov 2024 04:15:00 +0000

Type Values Removed Values Added
Description CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of confidentiality and integrity of controllers. To be successful, the attacker needs to inject themself inside the logical network while a valid user uploads or downloads a project file into the controller.
Weaknesses CWE-924
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published: 2024-11-13T04:06:09.279Z

Updated: 2024-11-13T15:34:19.535Z

Reserved: 2024-09-17T07:30:30.190Z

Link: CVE-2024-8933

cve-icon Vulnrichment

Updated: 2024-11-13T15:34:10.576Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-13T04:15:05.037

Modified: 2024-11-13T17:01:16.850

Link: CVE-2024-8933

cve-icon Redhat

No data.