

Pakistani Users Targeted in Military-Themed Email Scam Campaign – Active IOCs
June 24, 2024
CVE-2024-33001 – SAP NetWeaver and ABAP Platform Vulnerability
June 24, 2024
Pakistani Users Targeted in Military-Themed Email Scam Campaign – Active IOCs
June 24, 2024
CVE-2024-33001 – SAP NetWeaver and ABAP Platform Vulnerability
June 24, 2024Severity
Medium
Analysis Summary
CVE-2024-5557
Schneider Electric SpaceLogic AS-P and AS-B Automation Servers could allow a remote authenticated attacker to obtain sensitive information, caused by the insertion of sensitive information into log file. By gaining access to the log file, an attacker could exploit this vulnerability to obtain SNMP credentials information, and use this information to launch further attacks against the affected system.
Impact
- Information Disclosure
Indicators of Compromise
CVE
- CVE-2024-5557
Affected Vendors
Affected Products
- Schneider Electric SpaceLogic AS-P 5.0.3
- Schneider Electric SpaceLogic AS-B 5.0.3
Remediation
Refer to Schneider Electric Security Advisory for patch, upgrade or suggested workaround information.