CVE-2024-8070
CVSS 3.1 Score 8.5 of 10 (high)
Details
Published Oct 13, 2024
Updated: Oct 15, 2024
CWE ID 312
Summary
CVE-2024-8170 represents a vulnerability classified as CWE-312, where sensitive information, specifically test credentials, is stored in plaintext within a firmware binary. This issue poses a significant risk as the cleartext storage permits unauthorized access if the binary falls into the wrong hands. The vulnerability may affect various systems utilizing this specific firmware, and mitigation measures should include secure storage methods for credentials or updating the affected firmware to a patch that remedies this weakness.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.