PT-2024-4207 · Schneider Electric · Spacelogic As-B

Published

2024-06-11

·

Updated

2024-07-25

·

CVE-2024-5557

CVSS v2.0

5.5

Medium

VectorAV:A/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Schneider Electric SpaceLogic AS-P and SpaceLogic AS-B (affected versions not specified)
Description The issue is related to the exposure of sensitive information, specifically SNMP credentials, through log files. This could allow a remote attacker to obtain these credentials if they have access to the controller logs. The estimated number of potentially affected devices worldwide is not available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2024-04693
CVE-2024-5557

Affected Products

Spacelogic As-B