PT-2024-23844 · Plug&Track+1 · Sensor Net Connect V2+1

Diego Zaffaroni

·

Published

2024-07-31

·

Updated

2024-08-12

·

CVE-2024-31200

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Software (affected versions not specified)
Description The issue allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser. This is due to the insertion of sensitive information into sent data, affecting the administrative account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-31200

Affected Products

Sensor Net Connect V2
Sensor Net Connect Firmware V2