CVE-2024-8884
CVE-2024-8884
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
08 Oct 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that
could cause exposure of credentials when attacker has access to application on network over
http
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Schneider Electric · System Monitor application in Harmony Industrial PC HMIBMO/HMIBMI/HMIPSO/HMIBMP/HMIBMU/HMIPSP/HMIPEP seriesSchneider Electric · System Monitor application in Pro-face Industrial PC PS5000 seriesWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →