CVE-2024-8777
Estado: AnalizadaAlta (7.5)—
OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers can obtain plaintext credentials.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.54%
- Percentil entre todas las CVEs puntuadas: 44
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
- CWE-522
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-8777",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-8777",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-09-16T13:52:47.253305Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "twcert@cert.org.tw",
"affectedData": [
{
"vendor": "The SYSCOM Group",
"product": "OMFLOW",
"versions": [
{
"status": "affected",
"version": "1.1.6.0",
"versionType": "custom",
"lessThanOrEqual": "1.2.1.2"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:syscomgo:omflow:*:*:*:*:*:*:*:*"
],
"vendor": "syscomgo",
"product": "omflow",
"versions": [
{
"status": "affected",
"version": "1.1.6.0",
"versionType": "custom",
"lessThanOrEqual": "1.2.1.2"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-09-16T06:15:11.483",
"references": [
{
"url": "https://www.twcert.org.tw/en/cp-139-8072-928a5-2.html",
"tags": [
"Third Party Advisory"
],
"source": "twcert@cert.org.tw"
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-8071-46589-1.html",
"tags": [
"Third Party Advisory"
],
"source": "twcert@cert.org.tw"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-522"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers can obtain plaintext credentials."
},
{
"lang": "es",
"value": "OMFLOW de The SYSCOM Group tiene una vulnerabilidad de fuga de información que permite a atacantes remotos no autorizados leer configuraciones arbitrarias del sistema. Si la autenticación LDAP está habilitada, los atacantes pueden obtener credenciales en texto simple."
}
],
"lastModified": "2026-06-17T08:23:17.120",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:syscomgo:omflow:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F46C2FC2-89C8-4535-A426-AAE151888308",
"versionEndExcluding": "1.2.1.3",
"versionStartIncluding": "1.1.6.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "twcert@cert.org.tw"
}