PT-2024-24057 · Eaton · Eaton Foreseer

Joseph Yim

·

Published

2024-09-13

·

Updated

2025-08-26

·

CVE-2024-31415

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Eaton Foreseer (affected versions not specified)
Description The issue concerns the insecure storage of encryption keys used by the Eaton Foreseer software to securely store configurations for external servers on the host machine. These configurations are for various purposes, including network management and user management. The insecurely stored keys could potentially be abused to change or remove server configurations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-31415

Affected Products

Eaton Foreseer