Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8935

Опубликовано: 13 нояб. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.

EPSS

Процентиль: 4%
0.00018
Низкий

7.5 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 7.5
github
около 1 года назад

CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.

CVSS3: 7.5
fstec
около 1 года назад

Уязвимость алгоритма Диффи-Хеллмана микропрограммного обеспечения программируемых логических контроллеров (ПЛК) Schneider Electric Modicon M340 CPU BMXP34, позволяющая нарушителю реализовать атаку типа «человек посередине»

EPSS

Процентиль: 4%
0.00018
Низкий

7.5 High

CVSS3

Дефекты

CWE-290