CVE-2024-8933

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 13, 2024
CWE ID 924

Summary

CVE-2024-8933 is a newly disclosed vulnerability classified as CWE-924: Improper Enforcement of Message Integrity. This issue permits an attacker to gain unauthorized access to password hashes during file transfers between a controller and a user on the logical network. Successful exploitation could lead to denial of service and loss of both confidentiality and integrity. The attacker must intrude into the network during a valid user's file upload or download session to exploit the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share