CVE-2024-41156

LOW

Tropos - Info Disclosure

Title source: llm
STIX 2.1

Description

Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users with higher privilege of write access.

Scores

CVSS v3 2.7
EPSS 0.0017
EPSS Percentile 38.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-212
Status published
Products (3)
hitachienergy/tro610_firmware 9.1.0.0 - 9.2.0.5
hitachienergy/tro620_firmware 9.1.0.0 - 9.2.0.5
hitachienergy/tro670_firmware 9.1.0.0 - 9.2.0.5
Published Oct 29, 2024
Tracked Since Feb 18, 2026