cvelist/2024/4xxx/CVE-2024-4225.json
2024-04-30 07:00:33 +00:00

98 lines
3.2 KiB
JSON

{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2024-4225",
"ASSIGNER": "cve_disclosure@tech.gov.sg",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnerabilities to perform critical actions such as escalate user's privilege, steal user's credential, Cross Site Scripting (XSS) and Cross-Site Request Forgery (CSRF)."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-284 Improper Access Control, CWE-522 Insufficiently Protected Credentials, CWE-79 Improper Neutralization of Input During Web Page Generation",
"cweId": "CWE-284"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "DPS Telecom",
"product": {
"product_data": [
{
"product_name": "NetGuardian DIN Remote Telemetry Unit (RTU)",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "NGDIN_ST App v2.0D.0062"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://govtech-csg.github.io/security-advisories/2024/04/29/CVE-2024-4225.html",
"refsource": "MISC",
"name": "https://govtech-csg.github.io/security-advisories/2024/04/29/CVE-2024-4225.html"
}
]
},
"generator": {
"engine": "Vulnogram 0.1.0-dev"
},
"source": {
"discovery": "UNKNOWN"
},
"credits": [
{
"lang": "en",
"value": "Tan Inn Fung"
},
{
"lang": "en",
"value": "Goh Jing Loon"
}
],
"impact": {
"cvss": [
{
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
"version": "3.1"
}
]
}
}