Back

HIGH

CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss

Published Nov 13, 2024

Description

CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner schneider
Published Nov 13, 2024
Updated Nov 13, 2024
Reserved Sep 17, 2024
CISA Vulnrichment
Updated Nov 13, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner schneider
Published Nov 13, 2024
Updated Nov 13, 2024
Exploited since n/a
EUVD-2024-49493