CVE Vulnerabilities

CVE-2024-22808

Insecure Storage of Sensitive Information

Published: Apr 22, 2024 | Modified: Jul 03, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the cards name in the device memory.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

References