CVE-2024-41156: Medium severity hitachi energy tro610 vulnerability
Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users with higher privilege of write access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41156?
CVE-2024-41156 is classified as a medium severity vulnerability due to potential exposure of sensitive configuration information.
How does CVE-2024-41156 affect Tropos networks?
CVE-2024-41156 allows authenticated users with write access to export profile files that may contain valuable configuration information, which could be exploited by attackers.
How do I fix CVE-2024-41156?
To mitigate CVE-2024-41156, ensure that only trusted authenticated users have write access to profile files and regularly update the firmware to the latest version.
What versions are affected by CVE-2024-41156?
CVE-2024-41156 affects Hitachienergy Tro610, Tro620, and Tro670 firmware versions between 9.1.0.0 and 9.2.0.5.
What are the potential risks associated with CVE-2024-41156?
The risks associated with CVE-2024-41156 include unauthorized access to network configurations and potential network compromise due to leaked sensitive information.