« Volver al listado

CVE-2024-1309

Estado: AnalizadaAlta (7.5)—

Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-1309",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-1309",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-13T20:21:53.406350Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@honeywell.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@honeywell.com",
      "affectedData": [
        {
          "vendor": "Honeywell",
          "product": "Niagara Framework",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "Niagara AX 3.8.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "Niagara 4.1",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Windows",
            "Linux",
            "QNX"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-02-13T14:15:46.463",
  "references": [
    {
      "url": "https://process.honeywell.com",
      "tags": [
        "Product"
      ],
      "source": "psirt@honeywell.com"
    },
    {
      "url": "https://www.honeywell.com/us/en/product-security",
      "tags": [
        "Product"
      ],
      "source": "psirt@honeywell.com"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/417980",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "psirt@honeywell.com"
    },
    {
      "url": "https://process.honeywell.com",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.honeywell.com/us/en/product-security",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/417980",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@honeywell.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1.\n\n"
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de consumo de recursos no controlado en Honeywell Niagara Framework en Windows, Linux y QNX permite la suplantación de contenido. Este problema afecta a Niagara Framework: antes de Niagara AX 3.8.1, antes de Niagara 4.1."
    }
  ],
  "lastModified": "2026-06-17T07:03:56.973",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:honeywell:niagara_framework:*:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8335BC5-F8B3-4DA0-83CB-82E3E68A2C9C",
              "versionEndExcluding": "3.8.1"
            },
            {
              "criteria": "cpe:2.3:a:honeywell:niagara_framework:*:*:*:*:*:qnx:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3CC14A4-55BA-4B11-9A59-CDBCE57E7B42",
              "versionEndExcluding": "3.8.1"
            },
            {
              "criteria": "cpe:2.3:a:honeywell:niagara_framework:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8FEB7CC0-4C34-448D-ACEA-283D6E017D87",
              "versionEndExcluding": "3.8.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@honeywell.com"
}