Authentication Flaw in Schneider Electric’s Logcapture Feature
CVE-2024-8530
5.9MEDIUM
Summary
A significant vulnerability has been identified in Schneider Electric’s Logcapture feature, categorized as missing authentication for critical function (CWE-306). This flaw potentially exposes sensitive user data when unauthorized individuals can directly access previously generated 'logcaptures' archives via HTTPS. Organizations utilizing affected versions of Logcapture must take immediate action to apply necessary security patches and enhance their authentication protocols to mitigate risks associated with unauthorized data exposure.
Affected Version(s)
Data Center Expert Versions 8.1.1.3 and prior
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database