CVE-2024-8884 CRITICAL

CVE-2024-8884

Vendor Schneider Electric
Product System Monitor application in Harmony Industrial PC HMIBMO/HMIBMI/HMIPSO/HMIBMP/HMIBMU/HMIPSP/HMIPEP series
Weakness CWE-200 · Info exposure
Published October 8, 2024
Last update October 8, 2024

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has access to application on network over http

Key dates

02Disclosure timeline

October 8, 2024 CVE published
October 8, 2024 Record updated