CVE-2024-5434 Vulnerability Details

  /     /     /  

CVE-2024-5434 Metadata Quick Info

CVE Published: 28/05/2024 | CVE Updated: 01/08/2024 | CVE Year: 2024
Source: icscert | Vendor: Campbell Scientific | Product: CSI Web Server and RTMC
Status : PUBLISHED

CVE-2024-5434 Description

The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwords within that file are stored in a weakly encoded format. There is no known way to remotely access the file unless it has been manually renamed. However, if an attacker were to gain access to the file, passwords could be decoded and reused to gain access.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-261
CWE Name: CWE-261 Weak Encoding for Password
Source: Campbell Scientific

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).