OMFLOW from The SYSCOM Group has a vulnerability involving the exposure of sensitive data. This allows remote attackers who have logged into the system to obtain password hashes of all users and administrators.
History

Wed, 18 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 07:00:00 +0000

Type Values Removed Values Added
Description OMFLOW from The SYSCOM Group has a vulnerability involving the exposure of sensitive data. This allows remote attackers who have logged into the system to obtain password hashes of all users and administrators.
Title The SYSCOM Group OMFLOW - Exposure of Sensitive Data
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-09-18T06:53:53.016Z

Updated: 2024-09-18T13:28:23.529Z

Reserved: 2024-09-18T04:19:44.810Z

Link: CVE-2024-8969

cve-icon Vulnrichment

Updated: 2024-09-18T13:28:18.331Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-18T07:15:04.657

Modified: 2024-09-20T12:30:51.220

Link: CVE-2024-8969

cve-icon Redhat

No data.