CVE-2024-41974: WAGO: BACNet Service Property Modification Due to Permission Misconfiguration in Multiple Devices
Published Nov 18, 2024
·Updated
A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication.
Affected Software
1 affected component
WAGO BACNet
Event History
Nov 18, 2024
CVE Published
via MITRE·09:05 AM
Data Sourced
via MITRE·09:05 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-41974?
CVE-2024-41974 has a low severity rating as it involves a potential denial of service affecting BACNet communication.
2
How do I fix CVE-2024-41974?
To mitigate CVE-2024-41974, ensure proper permission assignments for critical resources in the BACNet service.
3
Who is affected by CVE-2024-41974?
CVE-2024-41974 affects installations using WAGO BACNet software.
4
What is the potential impact of CVE-2024-41974?
The potential impact of CVE-2024-41974 includes limited denial of service for BACNet services due to modified service properties.
5
What type of attacker can exploit CVE-2024-41974?
CVE-2024-41974 can be exploited by a low privileged remote attacker.