2024-12-08 03:06:42 +00:00

64 lines
2.3 KiB
JSON

{
"id": "CVE-2024-4225",
"sourceIdentifier": "cve_disclosure@tech.gov.sg",
"published": "2024-04-30T07:15:49.107",
"lastModified": "2024-11-21T09:42:25.453",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnerabilities to perform critical actions such as escalate user's privilege, steal user's credential, Cross Site Scripting (XSS) and Cross-Site Request Forgery (CSRF)."
},
{
"lang": "es",
"value": "DPS Telecom ha descubierto m\u00faltiples vulnerabilidades de seguridad en la interfaz web de la Unidad de Telemetr\u00eda Remota (RTU) DIN NetGuardian. Los atacantes pueden aprovechar esas vulnerabilidades de seguridad para realizar acciones cr\u00edticas como escalar los privilegios del usuario, robar la credencial del usuario, Cross Site Scripting (XSS) y Cross-Site Request Forgery (CSRF)."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cve_disclosure@tech.gov.sg",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 2.1,
"impactScore": 5.5
}
]
},
"weaknesses": [
{
"source": "cve_disclosure@tech.gov.sg",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"references": [
{
"url": "https://govtech-csg.github.io/security-advisories/2024/04/29/CVE-2024-4225.html",
"source": "cve_disclosure@tech.gov.sg"
},
{
"url": "https://govtech-csg.github.io/security-advisories/2024/04/29/CVE-2024-4225.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}