CVE-2024-41156
Last modified
CVE-2024-41156 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users with higher privilege of write access.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachienergy | Tro610 Firmware | >= 9.1.0.0, < 9.2.0.5 |
| Hitachienergy | Tro620 Firmware | >= 9.1.0.0, < 9.2.0.5 |
| Hitachienergy | Tro670 Firmware | >= 9.1.0.0, < 9.2.0.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-41156?
How severe is CVE-2024-41156?
How do I fix CVE-2024-41156?
Are you affected by CVE-2024-41156?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
