CVE-2024-10773

Published Dec 6, 2024

Last updated 3 months ago

Overview

Description
The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain full access to the device.
Source
psirt@sick.de
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@sick.de
CWE-912

Social media

Hype score
Not currently trending