PT-2024-29298 · Tropos · Tro600 Series Radios

Published

2024-10-29

·

Updated

2024-12-05

·

CVE-2024-41156

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions TRO600 series radios (affected versions not specified)
Description The issue concerns the extraction of profile files from TRO600 series radios in both plain-text and encrypted file formats. These profile files contain valuable configuration information about the Tropos network, which could be exploited by potential attackers. It is noted that profiles can only be exported by authenticated users who have a higher privilege level with write access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-41156

Affected Products

Tro600 Series Radios