CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-12142

Critical Severity
SVRS
75/100

CVSSv3
8.6/10

EPSS
0.0006/1

CVE-2024-12142: Sensitive information disclosure vulnerability exists. This could lead to unauthorized access to restricted web pages, potential modification, and even denial of service. The vulnerability occurs when specific web pages are modified and restricted functions are invoked.

The SVRS score of 75 suggests this is a high-risk issue requiring prompt attention. While not considered critical based on SOCRadar's scale, the potential for data exposure and service disruption makes it a significant threat. Successful exploitation of CVE-2024-12142 could have a serious impact on confidentiality and availability. The CWE-200 classification highlights the information exposure aspect of this vulnerability. Given it is tagged "In The Wild", active exploitation is a real possibility and immediate patching or mitigation is strongly advised.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:N
UI:N
S:U
C:L
I:L
A:H
2025-01-17

2025-02-12

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CISA Releases Nine Advisories Detailing Vulnerabilities and Exploits Surrounding ICS
Guru Baran2025-02-05
CISA Releases Nine Advisories Detailing Vulnerabilities and Exploits Surrounding ICS | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued nine new Industrial Control Systems (ICS) advisories, shedding light on critical vulnerabilities and exploits that could significantly impact industrial operations.  These advisories aim to provide actionable insights for securing ICS environments, which are integral to critical infrastructure sectors like energy, manufacturing, and transportation. The advisories […] The post CISA Releases Nine Advisories Detailing Vulnerabilities and Exploits Surrounding ICS appeared first
cybersecuritynews.com
rss
forum
news
Schneider Electric Modicon M340 and BMXNOE0100/0110, BMXNOR0200H
CISA2025-02-04
Schneider Electric Modicon M340 and BMXNOE0100/0110, BMXNOR0200H | View CSAF 1. EXECUTIVE SUMMARY CVSS v3 8.6 ATTENTION: Exploitable remotely/low attack complexity Vendor: Schneider Electric <
cisa.gov
rss
forum
news
CVE-2024-12142 | Schneider Electric Modicon M340 Processors information disclosure (SEVD-2025-014-05)
vuldb.com2025-01-17
CVE-2024-12142 | Schneider Electric Modicon M340 Processors information disclosure (SEVD-2025-014-05) | A vulnerability, which was classified as critical, was found in Schneider Electric Modicon M340 Processors, BMXNOE0100, BMXNOE0110 and BMXNOR0200H. Affected is an unknown function. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2024-12142. It is possible to launch the attack remotely. There is no exploit available. It is recommended to apply
vuldb.com
rss
forum
news

Social Media

Actively exploited CVE : CVE-2024-12142
1
0
0
[CVE-2024-12142: HIGH] Vulnerability CWE-200 exposes sensitive information to unauthorized actors, leading to data disclosure, page modification, and denial of service. Stay vigilant against cyber threats.#cybersecurity,#vulnerability https://t.co/LAk12kTYFE https://t.co/vjSl74Cv0N
0
0
0

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-014-05&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-014-05.pdf

CWE Details

CWE IDCWE NameDescription
CWE-200Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence