CVE-2024-45493
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/12/2024
Last modified:
17/12/2024
Description
An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow them to authenticate with an internal user account from the network (if they know their password).
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



