Products
Kastle Systems firmware
- before May 1, 2024
Source
ics-cert@hq.dhs.gov
Tags
CVE-2024-45862 details
Published : Sept. 19, 2024, 4:15 p.m.
Last Modified : Sept. 19, 2024, 4:15 p.m.
Last Modified : Sept. 19, 2024, 4:15 p.m.
Description
Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-312 | Cleartext Storage of Sensitive Information | The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere. |
References
URL | Source |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-24-263-05 | ics-cert@hq.dhs.gov |
This website uses the NVD API, but is not approved or certified by it.