← back
CVE-2024-47517mediumCWE-1230

Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.8epss 0.4%
exploitation probability
0.4%top 68% of all CVEs
observed exploitation
nono source reports it
In short

When a device loses connection to the ETM system, its expired administrator login tokens can be exposed to other devices. These old, unusable tokens are revealed even though they're no longer valid, which could expose sensitive credentials.

Technical detail

Units that time out from ETM access may leak expired administrator authentication tokens through the access mechanism. This exposure occurs via information disclosure when devices are temporarily disconnected or in a timeout state. While tokens are expired and unusable, their revelation could enable credential harvesting or reconnaissance attacks in environments where token formats or patterns are predictable.

Summary generated and translated by AI from the official description.
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L