CVE-2024-23767

An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.
Configurations

No configuration.

History

21 Nov 2024, 08:58

Type Values Removed Values Added
References
  • () https://github.com/claire-lex/anybus-hicp/blob/main/hicp_config.py -
References () https://sensepost.com/blog/2024/targeting-an-industrial-protocol-gateway/ - () https://sensepost.com/blog/2024/targeting-an-industrial-protocol-gateway/ -

11 Jul 2024, 15:05

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-287

27 Jun 2024, 12:47

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en la versión 3 del firmware HMS Anybus X-Gateway AB7832-F. El protocolo HICP permite cambios no autenticados en las configuraciones de red de un dispositivo.

26 Jun 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-26 21:15

Updated : 2024-11-21 08:58


NVD link : CVE-2024-23767

Mitre link : CVE-2024-23767

CVE.ORG link : CVE-2024-23767


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication