SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-31415

However, the keys used for this encryption were insecurely stored, which could be abused to possibly change or remove the server configuration.

HIGH 8.1EPSS 0.12%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely stored, which could be abused to possibly change or remove the server configuration.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS
0.12% probability · 2th percentile
CISA KEV
Not listed
Weakness
CWE-312, CWE-522
Affected
eaton/foreseer electrical power monitoring system
Source
CybersecurityCOE@eaton.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.