CVE-2024-31200 Vulnerability Details

  /     /     /  

CVE-2024-31200 Metadata Quick Info

CVE Published: 31/07/2024 | CVE Updated: 31/07/2024 | CVE Year: 2024
Source: Nozomi | Vendor: Plug&Track | Product: Sensor Net Connect V2
Status : PUBLISHED

CVE-2024-31200 Description

A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser.

Metrics

CVSS Version: 3.1 | Base Score: 4.2 MEDIUM
Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* PHYSICAL
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* NONE
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* NONE
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-201
CWE Name: CWE-201 Insertion of Sensitive Information Into Sent Data
Source: Plug&Track

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).