CVE-2024-8777

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
16/09/2024
Last modified:
20/09/2024

Description

OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers can obtain plaintext credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:syscomgo:omflow:*:*:*:*:*:*:*:* 1.1.6.0 (including) 1.2.1.3 (excluding)