CVE-2024-0860
Cleartext Transmission of Sensitive Information in Softing edgeConnector and edgeAggregator
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own requests.
El producto afectado es vulnerable a una transmisiĆ³n de texto plano de informaciĆ³n confidencial, lo que puede permitir a un atacante capturar paquetes para manipular sus propias solicitudes.
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the web console, which listens on TCP port 8099 by default. HTTP traffic to this port contains unprotected credentials. An attacker can leverage this vulnerability to bypass authentication on the system.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-01-24 CVE Reserved
- 2024-03-14 CVE Published
- 2024-03-30 EPSS Updated
- 2024-08-12 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-24-074-13 | Government Resource |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Softing Search vendor "Softing" | EdgeConnector Search vendor "Softing" for product "EdgeConnector" | 3.60 Search vendor "Softing" for product "EdgeConnector" and version "3.60" | en |
Affected
| ||||||
Softing Search vendor "Softing" | EdgeAggregator Search vendor "Softing" for product "EdgeAggregator" | 3.60 Search vendor "Softing" for product "EdgeAggregator" and version "3.60" | en |
Affected
|