of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the
controller and the engineering workstation while a valid user is establishing a communication session. This
vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49493 | CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks. |
Wed, 13 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Schneider-electric
Schneider-electric modicon M340 Bmxp341000 Schneider-electric modicon Mc80 Bmkc8020301 Schneider-electric modicon Momentum Unity M1e Processor |
|
| CPEs | cpe:2.3:h:schneider-electric:modicon_m340_bmxp341000:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_mc80_bmkc8020301:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_momentum_unity_m1e_processor:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Schneider-electric
Schneider-electric modicon M340 Bmxp341000 Schneider-electric modicon Mc80 Bmkc8020301 Schneider-electric modicon Momentum Unity M1e Processor |
|
| Metrics |
ssvc
|
Wed, 13 Nov 2024 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks. | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-11-13T15:31:54.906Z
Reserved: 2024-09-17T07:47:01.855Z
Link: CVE-2024-8935
Updated: 2024-11-13T15:31:26.833Z
Status : Deferred
Published: 2024-11-13T05:15:19.673
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-8935
No data.
OpenCVE Enrichment
No data.
EUVD