CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs man in the middle attack by intercepting the communication.
https://www.cisa.gov/news-events/ics-advisories/icsa-25-035-07
Published: 2025-01-17
Updated: 2026-04-15
Base Score: 7.3
Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:C/A:C
Severity: High
Base Score: 7.1
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H
Severity: High
Base Score: 6.1
Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: Medium
EPSS: 0.00023