CVE-2024-4225 HIGH

CVE-2024-4225: NGDIN_ST v2.0D.0062 - Multiple Vulnerabilities

Vendor Dps Telecom
Product NetGuardian DIN Remote Telemetry Unit (RTU)
Weakness CWE-284
Published April 30, 2024
Last update August 9, 2024

CVSS base score

7.6/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

What the vulnerability does

01Description

Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnerabilities to perform critical actions such as escalate user's privilege, steal user's credential, Cross Site Scripting (XSS) and Cross-Site Request Forgery (CSRF).

Key dates

02Disclosure timeline

April 30, 2024 CVE published
August 9, 2024 Record updated