← back
CVE-2024-47517

Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access

CVSS 6.8 MEDIUMEPSS 0.4%CWE-1230
In short

When a device loses connection to the ETM system, its expired administrator login tokens can be exposed to other devices. These old, unusable tokens are revealed even though they're no longer valid, which could expose sensitive credentials.

Technical detail

Units that time out from ETM access may leak expired administrator authentication tokens through the access mechanism. This exposure occurs via information disclosure when devices are temporarily disconnected or in a timeout state. While tokens are expired and unusable, their revelation could enable credential harvesting or reconnaissance attacks in environments where token formats or patterns are predictable.

Summary generated and translated by AI from the official description.
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →