Insecure Configuration Storage Risk Discovered in Eaton Foreseer Software
CVE-2024-31415
8.1HIGH
Key Information
- Vendor
- Eaton
- Status
- Foreseer
- Vendor
- CVE Published:
- 13 September 2024
Summary
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely stored, which could be abused to possibly change or remove the server configuration.
Affected Version(s)
Foreseer < 7.8.500
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database
Credit
Joseph Yim