CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss
of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the
controller and the engineering workstation while a valid user is establishing a communication session. This
vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.
Metrics
Affected Vendors & Products
References
History
Wed, 13 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Schneider-electric
Schneider-electric modicon M340 Bmxp341000 Schneider-electric modicon Mc80 Bmkc8020301 Schneider-electric modicon Momentum Unity M1e Processor |
|
CPEs | cpe:2.3:h:schneider-electric:modicon_m340_bmxp341000:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_mc80_bmkc8020301:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_momentum_unity_m1e_processor:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Schneider-electric
Schneider-electric modicon M340 Bmxp341000 Schneider-electric modicon Mc80 Bmkc8020301 Schneider-electric modicon Momentum Unity M1e Processor |
|
Metrics |
ssvc
|
Wed, 13 Nov 2024 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks. | |
Weaknesses | CWE-290 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: schneider
Published: 2024-11-13T04:10:09.599Z
Updated: 2024-11-13T15:31:54.906Z
Reserved: 2024-09-17T07:47:01.855Z
Link: CVE-2024-8935
Vulnrichment
Updated: 2024-11-13T15:31:26.833Z
NVD
Status : Awaiting Analysis
Published: 2024-11-13T05:15:19.673
Modified: 2024-11-13T17:01:16.850
Link: CVE-2024-8935
Redhat
No data.