CVE-2024-38434
July 21, 2024, 7:15 a.m.
Tags
CVSS Score
Product(s) Impacted
Unitronics Vision PLC
Description
Unitronics Vision PLC – CWE-676: Use of Potentially Dangerous Function may allow security feature bypass
Weaknesses
CWE-676
Use of Potentially Dangerous Function
The product invokes a potentially dangerous function that could introduce a vulnerability if it is used incorrectly, but the function can also be used safely.
CWE ID: 676Date
Published: July 21, 2024, 7:15 a.m.
Last Modified: July 21, 2024, 7:15 a.m.
Status : Received
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
cna@cyber.gov.il
CVSS Data
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Base Score
Exploitability Score
Impact Score
Base Severity
MEDIUMCVSS Vector String
The CVSS vector string provides an in-depth view of the vulnerability metrics.
View Vector StringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N