Sensitive Information at Risk of Cleartext Transmission
CVE-2024-0860
7.5HIGH
What is CVE-2024-0860?
CVE-2024-0860 involves a vulnerability that permits the cleartext transmission of sensitive data within ABC Vendor's XYZ Product. This flaw exposes data to potential interception by malicious actors, who may exploit this vulnerability to capture sensitive information packets. Consequently, attackers can craft their own requests, leading to unauthorized access and manipulation of the affected systems. Organizations utilizing XYZ Product are advised to assess their configurations and implement appropriate security measures to mitigate exposure.
Affected Version(s)
edgeAggregator Version 3.60
edgeConnector Version 3.60
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pan ZhenPeng (@Peterpan0927) and Li JianTao (@CurseRed) of STAR Labs SG Pte. Ltd. (@starlabs_sg) working with Trend Micro Zero Day Initiative reported these vulnerabilities to CISA. Claroty Team82 working with Trend Micro Zero Day Initiative reported these vulnerabilities to CISA
