after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper
with memory.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49494 | CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory. |
Wed, 13 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 Nov 2024 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory. | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-11-13T15:21:25.836Z
Reserved: 2024-09-17T07:48:38.234Z
Link: CVE-2024-8936
Updated: 2024-11-13T15:21:22.320Z
Status : Deferred
Published: 2024-11-13T05:15:20.540
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-8936
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:09:36Z
EUVD