CVE-2024-8933

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
13/11/2024
Last modified:
13/11/2024

Description

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel<br /> vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of<br /> confidentiality and integrity of controllers. To be successful, the attacker needs to inject themself inside the<br /> logical network while a valid user uploads or downloads a project file into the controller.