PT-2024-31660 · Msa · Fieldserver Gateway

Published

2024-12-10

·

Updated

2024-12-17

·

CVE-2024-45493

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MSA FieldServer Gateway versions 5.0.0 through 6.5.2
Description: An issue was discovered in the FieldServer Gateway, where an attacker can bypass the check for internal users, potentially allowing them to authenticate with an internal user account from the network if they know the password. The FieldServer Gateway has internal users whose access is supposed to be restricted to login locally on the device.
Recommendations: For versions 5.0.0 through 6.5.2, update to version 7.0.0 to resolve the issue. As a temporary workaround, consider restricting network access to internal user accounts until the update can be applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45493

Affected Products

Fieldserver Gateway