---
cve: "CVE-2024-31200"
severity: "MEDIUM"
cvss: 4.2
epss: "19%"
vendor: "Plug&Track"
kev: false
exploited: false
published: "2024-07-31 14:15:03"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T20:42:41+02:00"
---

# CVE-2024-31200

> 4.2 MEDIUM

## Beschreibung

A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser.

## CVSS-Vektor

```
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Physisch | good |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-201** — Insertion of Sensitive Information Into Sent Data
  The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

## Angriffsmuster (CAPEC)

- [CAPEC-12 — Choosing Message Identifier](https://capec.mitre.org/data/definitions/12.html) _(Severity: High)_
- [CAPEC-217 — Exploiting Incorrectly Configured SSL/TLS](https://capec.mitre.org/data/definitions/217.html)
- [CAPEC-612 — WiFi MAC Address Tracking](https://capec.mitre.org/data/definitions/612.html) _(Severity: Low)_
- [CAPEC-613 — WiFi SSID Tracking](https://capec.mitre.org/data/definitions/613.html) _(Severity: Low)_
- [CAPEC-618 — Cellular Broadcast Message Request](https://capec.mitre.org/data/definitions/618.html) _(Severity: Low)_
- [CAPEC-619 — Signal Strength Tracking](https://capec.mitre.org/data/definitions/619.html) _(Severity: Low)_
- [CAPEC-621 — Analysis of Packet Timing and Sizes](https://capec.mitre.org/data/definitions/621.html) _(Severity: Low)_
- [CAPEC-622 — Electromagnetic Side-Channel Attack](https://capec.mitre.org/data/definitions/622.html) _(Severity: Low)_

## Referenzen

- <https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31200>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-31200) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
