Sensitivity of Profile File Handling in Tropos Radios from Hitachi Energy
CVE-2024-41156
2.7LOW
Summary
The vulnerability concerns profile files associated with the TRO600 series radios from Hitachi Energy, which can be extracted in both plain-text and encrypted formats. These profile files contain critical configuration details about the Tropos network that could be leveraged by potential attackers. Although only authenticated users with elevated privileges can export these files, the risk lies in the potential for unauthorized access if security measures are not robustly implemented. Implementing strong data protection protocols is essential to prevent leakage of sensitive information.
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database