SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2024-28023

A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

MEDIUM 5.7EPSS 0.17%

Does this matter?

Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

CVSS 3.1
5.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
EPSS
0.17% probability · 6th percentile
CISA KEV
Not listed
Weakness
CWE-259
Source
cybersecurity@hitachienergy.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.