CVE-2024-5404: Ifm Moneo Appliance QHA210

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.

Affected products

  • Ifm Moneo Appliance QHA210: from 0.0, up to and including 1.13
  • Ifm Moneo Appliance QHA300: from 0.0, up to and including 1.13
  • Ifm Moneo Appliance QVA200: from 0.0, up to and including 1.13
  • Ifm Moneo For Micosoft Windows: from 0.0, up to and including 1.13
  • Ifm Moneo For Microsoft Windows: up to and including 1.13
  • Ifm Moneo QHA210: up to and including 1.13
  • Ifm Moneo QHA300: up to and including 1.13
  • Ifm Moneo QVA200: up to and including 1.13

Published 2024-06-03. Last modified 2026-06-17.