CVE-2024-13416
Severity CVSS v4.0:
Pending analysis
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
06/02/2025
Last modified:
21/02/2025
Description
Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log.<br />
<br />
<br />
<br />
<br />
2N has released an updated version 2.46 of 2N OS, where this vulnerability is mitigated. It is recommended that all customers update their devices to the latest 2N OS.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM