Authentication Flaw in Schneider Electric’s Logcapture Feature
CVE-2024-8530

5.9MEDIUM

Key Information:

Vendor
CVE Published:
11 October 2024

Summary

A significant vulnerability has been identified in Schneider Electric’s Logcapture feature, categorized as missing authentication for critical function (CWE-306). This flaw potentially exposes sensitive user data when unauthorized individuals can directly access previously generated 'logcaptures' archives via HTTPS. Organizations utilizing affected versions of Logcapture must take immediate action to apply necessary security patches and enhance their authentication protocols to mitigate risks associated with unauthorized data exposure.

Affected Version(s)

Data Center Expert Versions 8.1.1.3 and prior

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.