CVE-2024-46887

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' endpoint. This could allow an unauthenticated remote attacker to gain knowledge about current actual and configured maximum cycle times as well as about configured maximum communication load.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-05: 110-05
Referenced assets1 URL
Full discourse1 post
  • SHELLCODE@sh3ll_c0d3

    ⚙️ Siemens SIMATIC S7-1500 CVE-2024-46887: Auth bypass in embedded web server leaks diagnostic buffers & PLC telemetry to unauthenticated attackers. Read Blog: https://sh3llc0d3.com/blog/siemens-simatic-s7-1500-cpu-authentication-bypass-unauthenticated-telemetry-leakage-cve-2024-46887-icsa-24-284-10/ #sh3llc0d3 #shellcode #Hacktober #OTSecurity

    0000022
    109 followersView on X

Explore more