CVE-2024-8777

OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers can obtain plaintext credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:syscomgo:omflow:*:*:*:*:*:*:*:*

History

20 Sep 2024, 14:22

Type Values Removed Values Added
CPE cpe:2.3:a:syscomgo:omflow:*:*:*:*:*:*:*:*
CWE CWE-522
First Time Syscomgo
Syscomgo omflow
References () https://www.twcert.org.tw/en/cp-139-8072-928a5-2.html - () https://www.twcert.org.tw/en/cp-139-8072-928a5-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-8071-46589-1.html - () https://www.twcert.org.tw/tw/cp-132-8071-46589-1.html - Third Party Advisory

16 Sep 2024, 15:30

Type Values Removed Values Added
Summary
  • (es) OMFLOW de The SYSCOM Group tiene una vulnerabilidad de fuga de información que permite a atacantes remotos no autorizados leer configuraciones arbitrarias del sistema. Si la autenticación LDAP está habilitada, los atacantes pueden obtener credenciales en texto simple.

16 Sep 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-16 06:15

Updated : 2024-09-20 14:22


NVD link : CVE-2024-8777

Mitre link : CVE-2024-8777

CVE.ORG link : CVE-2024-8777


JSON object : View

Products Affected

syscomgo

  • omflow
CWE
CWE-522

Insufficiently Protected Credentials

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor