CVE-2024-8936
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Nov 13, 2024
CWE ID 20
Summary
CVE-2024-8936 is a newly discovered vulnerability classified as an Improper Input Validation issue (CWE-20). This weakness lies in the failure to properly validate user inputs, making it susceptible to Man-In-The-Middle (MITM) attacks. Successful MITM attacks can result in unauthorized access to the controller memory, potentially leading to a loss of confidentiality. A crafted Modbus function call is used to manipulate the memory after a successful MITM attack, exploiting this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.