CVE-2024-0860: Cleartext Transmission of Sensitive Information in Softing edgeConnector and edgeAggregator
Published Mar 14, 2024
·Updated
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own requests.
Affected Software
4 affected components
Softing edgeConnector
Softing edgeAggregator
Softing edgeAggregator=3.60
Softing edgeConnector=3.60
Remediation
Information
Update Softing edgeConnector and edgeAggregator to v3.70 or greater.
Event History
Mar 14, 2024
CVE Published
via MITRE·08:54 PM
Data Sourced
via MITRE·08:54 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0860?
CVE-2024-0860 is classified as a high-severity vulnerability.
2
What products are affected by CVE-2024-0860?
CVE-2024-0860 affects Softing edgeConnector and Softing edgeAggregator versions 3.60.
3
How do I fix CVE-2024-0860?
To fix CVE-2024-0860, ensure that sensitive information is transmitted over secure channels such as HTTPS.
4
What type of information is at risk in CVE-2024-0860?
CVE-2024-0860 exposes sensitive information due to cleartext transmission, which can be intercepted by attackers.
5
Could CVE-2024-0860 lead to other attacks?
Yes, attackers could use the information captured from CVE-2024-0860 to craft their own malicious requests.