CVE-2024-31415
Last modified
CVE-2024-31415 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely stored, which could be abused to possibly change or remove the server configuration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eaton | Foreseer Electrical Power Monitoring System | < 7.8.600 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-31415?
How severe is CVE-2024-31415?
How do I fix CVE-2024-31415?
Are you affected by CVE-2024-31415?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
