Insecure Configuration Storage Risk Discovered in Eaton Foreseer Software

CVE-2024-31415
8.1HIGH

Key Information

Vendor
Eaton
Status
Foreseer
Vendor
CVE Published:
13 September 2024

Summary

The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely stored, which could be abused to possibly change or remove the server configuration.

Affected Version(s)

Foreseer < 7.8.500

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Joseph Yim
.