PT-2024-23844 · Plug&Track+1 · Sensor Net Connect V2+1

·

CVE-2024-31200

·

Published

2024-07-31

·

Updated

2024-08-12

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Software (affected versions not specified)
Description The issue allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser. This is due to the insertion of sensitive information into sent data, affecting the administrative account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-31200

Affected Products

Sensor Net Connect V2
Sensor Net Connect Firmware V2