PT-2024-2277 · Softing · Softing Edgeconnector 840D+5
Cursered
+3
·
Published
2024-03-14
·
Updated
2024-03-29
·
CVE-2024-0860
CVSS v2.0
8.3
High
| Vector | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Softing edgeAggregator and Softing edgeConnector modules (affected versions not specified)
Softing edgeConnector Modbus (affected versions not specified)
Softing edgeConnector 840D (affected versions not specified)
Softing edgeConnector Fanuc CNC (affected versions not specified)
Softing edgeConnector Siemens (affected versions not specified)
Description
The issue is related to the transmission of credentials in cleartext, which may allow a remote attacker to capture packets and craft their own requests, potentially leading to unauthorized access to protected information. This could enable an attacker to bypass authentication.
Recommendations
For Softing edgeAggregator, consider disabling the transmission of credentials in cleartext until a patch is available.
For Softing edgeConnector modules, restrict access to sensitive information to minimize the risk of exploitation.
For Softing edgeConnector Modbus, Softing edgeConnector 840D, Softing edgeConnector Fanuc CNC, and Softing edgeConnector Siemens, avoid using cleartext transmission of credentials in the affected API endpoints until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Softing Edgeaggregator
Softing Edgeconnector
Softing Edgeconnector 840D
Softing Edgeconnector Fanuc Cnc
Softing Edgeconnector Modbus
Softing Edgeconnector Siemens