66% (52) 299 views 4 pages

EcoStruxure IT Gateway Security Notification (CVE-2024-10575)

AI-enhanced description

This document details a critical missing authorization vulnerability (CVE-2024-10575) in EcoStruxure™ IT Gateway versions 1.21.0.6, 1.22.0.3, 1.22.1.5, and 1.23.0.4, which could allow unauthorized network access and control of the Gateway or retrieval of sensitive information. The recommended remediation is to update to version 1.23.1.10, with additional mitigations including network isolation and firewall implementation for those who cannot apply the fix immediately.

Uploaded by noah-Jannes
Download
/ 4
Loading document…