CVE-2024-8933
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 13, 2024
CWE ID 924
Summary
CVE-2024-8933 is a newly disclosed vulnerability classified as CWE-924: Improper Enforcement of Message Integrity. This issue permits an attacker to gain unauthorized access to password hashes during file transfers between a controller and a user on the logical network. Successful exploitation could lead to denial of service and loss of both confidentiality and integrity. The attacker must intrude into the network during a valid user's file upload or download session to exploit the vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.