CVE-2024-46887

The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' endpoint. This could allow an unauthenticated remote attacker to gain knowledge about current actual and configured maximum cycle times as well as about configured maximum communication load.
Configurations

No configuration.

History

08 Apr 2025, 21:15

Type Values Removed Values Added
CWE CWE-862

27 Jan 2025, 18:15

Type Values Removed Values Added
CWE CWE-862

Information

Published : 2024-10-08 09:15

Updated : 2025-04-08 21:15


NVD link : CVE-2024-46887

Mitre link : CVE-2024-46887

CVE.ORG link : CVE-2024-46887


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel