CVE-2024-21869

MEDIUM

Rapid SCADA <5.8.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker with local access to see them.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-011-03

Scores

CVSS v3 6.2
EPSS 0.0016
EPSS Percentile 5.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522 CWE-256
Status published
Products (1)
rapidscada/rapid_scada < 5.8.4
Published Feb 02, 2024
Tracked Since Feb 18, 2026