CVE-2024-31416 MEDIUM

CVE-2024-31416

Vendor Eaton
Product Foreseer
Weakness CWE-190
Published September 13, 2024
Last update August 26, 2025

CVSS base score

5.6/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L

What the vulnerability does

01Description

The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of this security flaw by a bad actor may result in excessive memory consumption or integer overflow.

Key dates

02Disclosure timeline

September 13, 2024 CVE published
August 26, 2025 Record updated