CVE-2024-45032: Critical severity Industrial Edge Industrial Edge Management Pro vulnerability
A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.3.1-1). Affected components do not properly validate the device tokens. This could allow an unauthenticated remote attacker to impersonate other devices onboarded to the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45032?
CVE-2024-45032 is considered a critical vulnerability due to its potential for unauthenticated remote exploit.
How do I fix CVE-2024-45032?
To fix CVE-2024-45032, upgrade Industrial Edge Management Pro to version 1.9.5 or later and Industrial Edge Management Virtual to version 2.3.1-1 or later.
What can an attacker do with CVE-2024-45032?
An attacker can impersonate other devices by exploiting the insufficient validation of device tokens in the affected software.
Which versions of the software are affected by CVE-2024-45032?
All versions of Industrial Edge Management Pro below 1.9.5 and Industrial Edge Management Virtual below 2.3.1-1 are affected by CVE-2024-45032.
Is authentication required to exploit CVE-2024-45032?
No, CVE-2024-45032 can be exploited by unauthenticated remote attackers.