PT-2024-30295 · Automationdirect · Directlogic H2-Dm1E+1

Daniel Davenport

+3

·

Published

2024-09-13

·

Updated

2024-11-19

·

CVE-2024-43099

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue concerns a session hijacking attack targeting the application layer's control mechanism. This mechanism manages authenticated sessions between a host PC and a Programmable Logic Controller (PLC). During these sessions, a session key is used for security. However, if an attacker captures this session key, they can inject traffic into an ongoing authenticated session. To achieve this, the attacker must also spoof both the IP address and the MAC address of the originating host, which is typical of session-based attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-43099

Affected Products

Directlogic H2-Dm1E
H2-Dm1E Firmware