CVE-2024-8935
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss
of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the
controller and the engineering workstation while a valid user is establishing a communication session. This
vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.
CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-09-17 CVE Reserved
- 2024-11-13 CVE Published
- 2024-11-13 CVE Updated
- 2025-04-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-290: Authentication Bypass by Spoofing
CAPEC
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider Electric Search vendor "Schneider Electric" | Modicon MC80 (part Numbers BMKC80) Search vendor "Schneider Electric" for product "Modicon MC80 (part Numbers BMKC80)" | <= Search vendor "Schneider Electric" for product "Modicon MC80 (part Numbers BMKC80)" and version " <= " | en |
Affected
| ||||||
Schneider Electric Search vendor "Schneider Electric" | Modicon Momentum Unity M1E Processor (171CBU*) Search vendor "Schneider Electric" for product "Modicon Momentum Unity M1E Processor (171CBU*)" | <= Search vendor "Schneider Electric" for product "Modicon Momentum Unity M1E Processor (171CBU*)" and version " <= " | en |
Affected
|