CVE-2024-46887

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Jan 27, 2025
CWE ID 288
CWE ID 862

Summary

CVE-2024-46887 is a vulnerability affecting certain web servers. The issue lies in the failure to authenticate user requests to the '/ClientArea/RuntimeInfoData.mwsl' endpoint. This flaw can be exploited by unauthenticated remote attackers, allowing them to obtain sensitive information about actual and configured maximum cycle times and communication loads. This vulnerability poses a potential risk for unauthorized data collection and could lead to denial-of-service attacks. Devices with this weakness should be updated promptly to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share