CVE-2024-41156
2.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.2 / Impact: 1.4
Source: NVD
Description
Profile files from TRO600 series radios are extracted in plain-text
and encrypted file formats. Profile files provide potential attackers
valuable configuration information about the Tropos network. Profiles
can only be exported by authenticated users with higher privilege of write access.
Affected (3)
Products: Hitachienergy: Tro610 Firmware, Tro620 Firmware, Tro670 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.1.0.0 to 9.2.0.5 |
| Running on/with | Platform Versions |
|---|---|
Hitachienergy Tro610 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.1.0.0 to 9.2.0.5 |
| Running on/with | Platform Versions |
|---|---|
Hitachienergy Tro620 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.1.0.0 to 9.2.0.5 |
| Running on/with | Platform Versions |
|---|---|
Hitachienergy Tro670 | All versions |
References (1)
Source: cybersecurity@hitachienergy.com
Vendor Advisory
Timeline
No history available yet.