An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow them to authenticate with an internal user account from the network (if they know their password).
References
Configurations
No configuration.
History
17 Dec 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow them to authenticate with an internal user account from the network (if they know their password). |
13 Dec 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
|
11 Dec 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-862 |
10 Dec 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-10 17:15
Updated : 2024-12-17 19:15
NVD link : CVE-2024-45493
Mitre link : CVE-2024-45493
CVE.ORG link : CVE-2024-45493
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization