PT-2024-19425 · Hitachi Energy · Asset Suite Eam+1

Published

2024-03-26

·

Updated

2024-03-27

·

CVE-2024-2244

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue concerns a REST service authentication anomaly where a "valid username/no password" credential combination allows for successful service invocation during batch job processing. This anomaly does not occur with other credential combinations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-2244

Affected Products

Asset Suite Eam
Asset Suite