PT-2024-10396 · Unknown · Rapid Scada

Published

2024-09-11

·

Updated

2024-09-29

·

CVE-2024-47221

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Rapid SCADA versions through 5.8.4
Description The issue is related to weak password requirements in the Rapid SCADA system, specifically in the CheckUser function within ScadaServerEngine/MainLogic.cs. This allows an empty password, which can be exploited by a remote attacker to impact the integrity of protected information.
Recommendations For versions through 5.8.4, consider disabling the CheckUser function in ScadaServerEngine/MainLogic.cs as a temporary workaround until a patch is available. Restrict access to the ScadaServerEngine/MainLogic.cs module to minimize the risk of exploitation. Avoid using empty passwords in the affected system until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00911
CVE-2024-47221

Affected Products

Rapid Scada