CVE-2024-8935
CVSS V2 None
CVSS V3 None
Description
CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss
of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the
controller and the engineering workstation while a valid user is establishing a communication session. This
vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.
Overview
- CVE ID
- CVE-2024-8935
- Assigner
- schneider
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-11-13T04:10:09.599Z
- Last Modified Date
- 2024-11-13T04:10:09.599Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://download.schneider-electric.com/doc/SEVD-2024-317-02/SEVD-2024-317-02.pdf |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-8935 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8935 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-11-13 13:13:50 | Added to TrackCVE |