Inadequate Encryption Strength in Location Intelligence family - CVE-2024-41681
Published: August 14, 2024
Vulnerability identifier: #VU95993
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-41681
CWE-ID: CWE-326
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the web server is configured to support weak ciphers by default. A remote attacker on the local network can read and modify any data passed over the connection between legitimate clients and the affected device.
Affected software
Location Intelligence family
How to mitigate CVE-2024-41681
Install updates from vendor's website.
Location Intelligence family - update to 4.4