Back

HIGH

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel

Published Nov 13, 2024

Description

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of confidentiality and integrity of controllers. To be successful, the attacker needs to inject themself inside the logical network while a valid user uploads or downloads a project file into the controller.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner schneider
Published Nov 13, 2024
Updated Nov 13, 2024
Reserved Sep 17, 2024
CISA Vulnrichment
Updated Nov 13, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a