PT-2024-8680 · Unknown · Microscada X Sys600
Published
2024-08-27
·
Updated
2024-10-30
·
CVE-2024-3982
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MicroSCADA X SYS600 (affected versions not specified)
Description
The issue is related to bypassing the authentication procedure in the MicroSCADA X SYS600 system. An attacker with local access to the machine where MicroSCADA X SYS600 is installed could enable session logging and try to exploit session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.
Recommendations
As a temporary workaround, consider disabling the session logging feature until a patch is available.
Restrict access to the MicroSCADA X SYS600 system to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microscada X Sys600