Authentication Flaw in Schneider Electric’s Logcapture Feature
CVE-2024-8530
5.9MEDIUM
Key Information:
- Vendor
Schneider Electric
- Status
- Vendor
- CVE Published:
- 11 October 2024
What is CVE-2024-8530?
A significant vulnerability has been identified in Schneider Electric’s Logcapture feature, categorized as missing authentication for critical function (CWE-306). This flaw potentially exposes sensitive user data when unauthorized individuals can directly access previously generated 'logcaptures' archives via HTTPS. Organizations utilizing affected versions of Logcapture must take immediate action to apply necessary security patches and enhance their authentication protocols to mitigate risks associated with unauthorized data exposure.
Affected Version(s)
Data Center Expert Versions 8.1.1.3 and prior