PT-2024-2277 · Softing · Softing Edgeconnector 840D+5

Cursered

+3

·

Published

2024-03-14

·

Updated

2024-03-29

·

CVE-2024-0860

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Softing edgeAggregator and Softing edgeConnector modules (affected versions not specified) Softing edgeConnector Modbus (affected versions not specified) Softing edgeConnector 840D (affected versions not specified) Softing edgeConnector Fanuc CNC (affected versions not specified) Softing edgeConnector Siemens (affected versions not specified)
Description The issue is related to the transmission of credentials in cleartext, which may allow a remote attacker to capture packets and craft their own requests, potentially leading to unauthorized access to protected information. This could enable an attacker to bypass authentication.
Recommendations For Softing edgeAggregator, consider disabling the transmission of credentials in cleartext until a patch is available. For Softing edgeConnector modules, restrict access to sensitive information to minimize the risk of exploitation. For Softing edgeConnector Modbus, Softing edgeConnector 840D, Softing edgeConnector Fanuc CNC, and Softing edgeConnector Siemens, avoid using cleartext transmission of credentials in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02210
CVE-2024-0860
ZDI-24-353

Affected Products

Softing Edgeaggregator
Softing Edgeconnector
Softing Edgeconnector 840D
Softing Edgeconnector Fanuc Cnc
Softing Edgeconnector Modbus
Softing Edgeconnector Siemens