PT-2024-10144 · Schneider Electric · Bmxnoe0100+3

Published

2024-12-04

·

Updated

2025-02-13

·

CVE-2024-12142

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
The issue at hand is related to a sensitive information exposure flaw, which could lead to the disclosure of restricted web pages, modification of web pages, and denial of service when specific web pages are modified and restricted functions are invoked. This flaw is identified by the CWE-200 designation, indicating Exposure of Sensitive Information to an Unauthorized Actor. The potential impact includes information disclosure, page modification, and service disruption, emphasizing the need for vigilance against cyber threats. No specific software or chipset models are mentioned in the provided descriptions, but the issue seems to be related to web page management and access control. An exploit for this issue may exist, as hinted by the provided links, but the specifics of the exploit are not detailed in the given information. It's crucial for affected parties to stay informed and take necessary precautions to mitigate potential risks. #CWE200 #ExposureOfSensitiveInformation #CyberThreats #InformationDisclosure #DenialOfService #WebPageSecurity #AccessControl #CyberSecurity

Fix

DoS

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-00417
CVE-2024-12142

Affected Products

Bmxnoe0100
Bmxnoe0110
Bmxnor0200H
Modicon M340