« Volver al listado

CVE-2024-8419

Estado: AplazadaAlta (7.5)—

The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authentication.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N/AC:L/PR:N/UI:N indica vulnerabilidad de red sin autenticación. Falta de validación de autenticación (CWE-306) permite ataque remoto no autenticado que pone el sistema en estado fail-safe, consistente con DoS. No hay evidencia explícita de acceso a credenciales o identidades.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-8419",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-8419",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-06-30T15:01:59.417077Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "ifm electronic GmbH",
          "product": "ifm Smart PLC AC402s",
          "versions": [
            {
              "status": "affected",
              "version": "4.04",
              "lessThan": "4.3.17",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.8"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ifm electronic GmbH",
          "product": "ifm Smart PLC AC422s",
          "versions": [
            {
              "status": "affected",
              "version": "4.04",
              "lessThan": "4.3.17",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.8"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ifm electronic GmbH",
          "product": "ifm Smart PLC AC424s",
          "versions": [
            {
              "status": "affected",
              "version": "4.04",
              "lessThan": "4.3.17",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.8"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ifm electronic GmbH",
          "product": "ifm Smart PLC AC432s",
          "versions": [
            {
              "status": "affected",
              "version": "4.04",
              "lessThan": "4.3.17",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.8"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ifm electronic GmbH",
          "product": "ifm Smart PLC AC434s",
          "versions": [
            {
              "status": "affected",
              "version": "4.04",
              "lessThan": "4.3.17",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.8"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-06-30T10:15:24.590",
  "references": [
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2024-061",
      "source": "info@cert.vde.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authentication."
    },
    {
      "lang": "es",
      "value": "El endpoint aloja un script que permite a un atacante remoto no autorizado poner el sistema en un estado a prueba de fallas a través de la red debido a la falta de autenticación."
    }
  ],
  "lastModified": "2026-06-17T08:22:32.920",
  "sourceIdentifier": "info@cert.vde.com"
}