← Back

CVE-2024-31200

nvd nist
Published: Jul 31, 2024Modified: Aug 12, 2024

JSON object

Loading...
4.6
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.9 / Impact: 3.6
Source: NVD

Description

A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser.

Affected (1)

1 product
Sensor Net Connect Firmware V2
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.24
Running on/withPlatform Versions
Proges
Sensor Net Connect V2
All versions

References (1)

Source: prodsec@nozominetworks.com
Third Party Advisory

Timeline

No history available yet.