CVE-2024-45370 Details
Description
An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy Config System 2.6.1.0. A specially crafted database record can lead to unauthorized access. An attacker can modify a local database to trigger this vulnerability.
A vulnerability allowing authentication bypass has been identified in the user profile management feature of Socomec Easy Config System version 2.6.1.0. This vulnerability arises from the application's reliance on a local SQLite database that contains password hashes and a field indicating whether a password is required for each user profile. An attacker with system access can modify the database to disable the password requirement, granting unauthorized access to the application without a password. This exploitation allows access to all configuration items of connected devices.
Socomec has released a patch for this vulnerability in version 3.1 of the Easy Config System. Users are advised to update to this version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 1, 2025CISA-ADP
Assessed Dec 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-302 | Authentication Bypass by Assumed-Immutable Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Socomec Easy Config System | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 1, 2025 | CVE Modified | CVE |
| Dec 1, 2025 | New CVE Received | [email protected] |
Volerion