CVE-2024-8935
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 13, 2024
CWE ID 290
Summary
CVE-2024-8935 is a newly identified vulnerability, classified as an Authentication Bypass by Spoofing (CWE-290) issue. This vulnerability can be exploited during Man-In-The-Middle (MITM) attacks, allowing unauthorized access to controllers through spoofed communication between the controller and an engineering workstation. The vulnerability is an inherent weakness in the Diffie Hellman algorithm, which does not offer protection against such attacks, potentially leading to denial of service and loss of confidentiality and integrity.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.