CVE-2024-49399 – Missing Authentication for Critical Function in Elvaco M-Bus Metering Gateway CMe3100
https://notcve.org/view.php?id=CVE-2024-49399
The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak information. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01 • CWE-306: Missing Authentication for Critical Function •
CVE-2024-49398 – Unrestricted Upload of File with Dangerous Type in Elvaco M-Bus Metering Gateway CMe3100
https://notcve.org/view.php?id=CVE-2024-49398
The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2024-49397 – Cross-site Scripting in Elvaco M-Bus Metering Gateway CMe3100
https://notcve.org/view.php?id=CVE-2024-49397
The affected product is vulnerable to a cross-site scripting attack which may allow an attacker to bypass authentication and takeover admin accounts. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-49396 – Insufficiently Protected Credentials in Elvaco M-Bus Metering Gateway CMe3100
https://notcve.org/view.php?id=CVE-2024-49396
The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01 • CWE-522: Insufficiently Protected Credentials •