9.2
CVE-2024-8938
- EPSS 0.31%
- Veröffentlicht 13.11.2024 05:15:25
- Zuletzt bearbeitet 13.11.2024 17:01:16
- Quelle cybersecurity@se.com
- Teams Watchlist Login
- Unerledigt Login
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call to tamper with memory area involved in memory size computation.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerschneider-electric
≫
Produkt
modicon_m340
Default Statusunaffected
Version <
SV3.65
Version
0
Status
affected
Herstellerschneider-electric
≫
Produkt
modicon_mc80
Default Statusunknown
Version <
*
Version
0
Status
affected
Herstellerschneider-electric
≫
Produkt
modicon_momentum_unity_m1e_processor
Default Statusunknown
Version <
*
Version
0
Status
affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.31% | 0.536 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
cybersecurity@se.com | 9.2 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
cybersecurity@se.com | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.