CVE-2024-8530

MEDIUM

Missing Authentication - Info Disclosure

Title source: llm
STIX 2.1

Description

CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by HTTPS.

Scores

CVSS v3 5.9
EPSS 0.0054
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
Schneider Electric/Data Center Expert Versions 8.1.1.3 and prior
Published Oct 11, 2024
Tracked Since Feb 18, 2026