CVE-2024-45494

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe shared secret that is static in all affected firmware versions.
Configurations

No configuration.

History

17 Dec 2024, 19:15

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en los módulos integrados y las puertas de enlace FieldServer de MSA Safety con revisiones de compilación anteriores a la 7.0.0. El módulo de puerta de enlace FieldServer tiene una cuenta de usuario administrativa compartida que se utiliza internamente en todos los dispositivos. La autenticación para este usuario se implementa a través de un secreto compartido no seguro que es estático en todas las versiones de firmware afectadas.
Summary (en) An issue was discovered in MSA Safety FieldServer Gateways and Embedded Modules with build revisions before 7.0.0. The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe shared secret that is static in all affected firmware versions. (en) An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe shared secret that is static in all affected firmware versions.

11 Dec 2024, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-276

10 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 17:15

Updated : 2024-12-17 19:15


NVD link : CVE-2024-45494

Mitre link : CVE-2024-45494

CVE.ORG link : CVE-2024-45494


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions