← back
CVE-2024-7408

Information Disclosure Vulnerability in Airveda Air Quality Monitor

CVSS 8.6 HIGHEPSS 0.3%CWE-319
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.6EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
09 Aug 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker in close proximity could exploit this vulnerability by capturing Wi-Fi traffic of Airveda-AP. Successful exploitation of this vulnerability could allow the attacker to cause Evil Twin attack on the targeted system.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:H/SI:H/SA:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →