CVE Vulnerabilities

CVE-2024-23766

Use of GET Request Method With Sensitive Query Strings

Published: Jun 26, 2024 | Modified: Jul 03, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least most of its modules). An attacker can use this feature to carry out a denial of service attack by continuously sending GET requests to that URL.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Potential Mitigations

References