PT-2024-31660 · Msa · Fieldserver Gateway
Published
2024-12-10
·
Updated
2024-12-17
·
CVE-2024-45493
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
MSA FieldServer Gateway versions 5.0.0 through 6.5.2
Description:
An issue was discovered in the FieldServer Gateway, where an attacker can bypass the check for internal users, potentially allowing them to authenticate with an internal user account from the network if they know the password. The FieldServer Gateway has internal users whose access is supposed to be restricted to login locally on the device.
Recommendations:
For versions 5.0.0 through 6.5.2, update to version 7.0.0 to resolve the issue. As a temporary workaround, consider restricting network access to internal user accounts until the update can be applied.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fieldserver Gateway