8.3
CVE-2024-8937
- EPSS 0.17%
- Veröffentlicht 13.11.2024 05:15:22
- Zuletzt bearbeitet 13.11.2024 17:01:16
- Quelle cybersecurity@se.com
- Teams Watchlist Login
- Unerledigt Login
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful Man-In-The Middle attack followed by sending a crafted Modbus function call to tamper with memory area involved in the authentication process.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSchneider Electric
≫
Produkt
Modicon M340 CPU (part numbers BMXP34*)
Default Statusunaffected
Version
Versions prior to SV3.65
Status
affected
HerstellerSchneider Electric
≫
Produkt
Modicon MC80 (part numbers BMKC80)
Default Statusunaffected
Version
All versions
Status
affected
HerstellerSchneider Electric
≫
Produkt
Modicon Momentum Unity M1E Processor (171CBU*)
Default Statusunaffected
Version
All Versions
Status
affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.17% | 0.382 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
cybersecurity@se.com | 8.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
cybersecurity@se.com | 6.5 | 2.2 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.