CVE-2024-6421: Pepperl+Fuchs: Incorrectly configured FTP-Server in OIT Products
Published Jul 10, 2024
·Updated
An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.
Affected Software
8 affected components
All of the following
Pepperl-fuchs Oit700-f113-b12-cb Firmware<=2.11.0
Pepperl-fuchs Oit700-f113-b12-cb
All of the following
Pepperl-fuchs Oit500-f113-b12-cb Firmware<=2.11.0
Pepperl-fuchs Oit500-f113-b12-cb
All of the following
Pepperl-fuchs Oit200-f113-b12-cb Firmware<=2.11.0
Pepperl-fuchs Oit200-f113-b12-cb
All of the following
Pepperl-fuchs Oit1500-f113-b12-cb Firmware<=2.11.0
Pepperl-fuchs Oit1500-f113-b12-cb
Event History
Jul 10, 2024
CVE Published
via MITRE·07:36 AM
Data Sourced
via MITRE·07:36 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-6421?
CVE-2024-6421 has a severity rating that may allow unauthenticated remote attackers to access sensitive device information.
2
How do I fix CVE-2024-6421?
To address CVE-2024-6421, reconfigure the FTP service to ensure that it is not exposed to unauthorized access.
3
Which devices are affected by CVE-2024-6421?
CVE-2024-6421 affects multiple Pepperl+Fuchs OIT series firmware versions up to 2.11.0.
4
Can CVE-2024-6421 lead to data breaches?
Yes, CVE-2024-6421 can potentially lead to data breaches due to unauthorized access to sensitive device information.
5
Is there a patch available for CVE-2024-6421?
As of now, it is recommended to check with the vendor for any available patches or recommended updates regarding CVE-2024-6421.