PT-2024-30295 · Automationdirect · Directlogic H2-Dm1E+1
Daniel Davenport
+3
·
Published
2024-09-13
·
Updated
2024-11-19
·
CVE-2024-43099
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
No specific software or versions are mentioned in the provided descriptions.
Description
The issue concerns a session hijacking attack targeting the application layer's control mechanism. This mechanism manages authenticated sessions between a host PC and a Programmable Logic Controller (PLC). During these sessions, a session key is used for security. However, if an attacker captures this session key, they can inject traffic into an ongoing authenticated session. To achieve this, the attacker must also spoof both the IP address and the MAC address of the originating host, which is typical of session-based attacks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directlogic H2-Dm1E
H2-Dm1E Firmware