4.5
CVE-2024-5557
- EPSS 0.11%
- Veröffentlicht 12.06.2024 17:15:51
- Zuletzt bearbeitet 21.11.2024 09:47:55
- Quelle cybersecurity@se.com
- CVE-Watchlists
- Unerledigt
CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Spacelogic As-b Firmware Version < 6.0.1
Schneider-electric ≫ Spacelogic As-p Firmware Version < 6.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.304 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.5 | 0.9 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| cybersecurity@se.com | 4.5 | 0.9 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.