Inadequate Encryption Strength in Location Intelligence family - CVE-2024-41681

 

Inadequate Encryption Strength in Location Intelligence family - CVE-2024-41681

Published: August 14, 2024


Vulnerability identifier: #VU95993
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-41681
CWE-ID: CWE-326
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the web server is configured to support weak ciphers by default. A remote attacker on the local network can read and modify any data passed over the connection between legitimate clients and the affected device.


Affected software

Location Intelligence family

How to mitigate CVE-2024-41681

Install updates from vendor's website.

Location Intelligence family - update to 4.4

External References

Related Security Bulletins