← Zuruck zu CVEs
CVE-2024-43692
CRITICAL9.8
Beschreibung
An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht9/25/2024
Zuletzt geandert10/1/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
doverfuelingsolutions:progauge_maglink_lx4_consoledoverfuelingsolutions:progauge_maglink_lx4_console_firmwaredoverfuelingsolutions:progauge_maglink_lx_consoledoverfuelingsolutions:progauge_maglink_lx_console_firmware
Schwachen (CWE)
CWE-288
Referenzen
https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-04(ics-cert@hq.dhs.gov)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.