CVE-2024-8936

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Nov 13, 2024
CWE ID 20

Summary

CVE-2024-8936 is a newly discovered vulnerability classified as an Improper Input Validation issue (CWE-20). This weakness lies in the failure to properly validate user inputs, making it susceptible to Man-In-The-Middle (MITM) attacks. Successful MITM attacks can result in unauthorized access to the controller memory, potentially leading to a loss of confidentiality. A crafted Modbus function call is used to manipulate the memory after a successful MITM attack, exploiting this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share