Lucene search

K
cveSiemensCVE-2024-35210
HistoryJun 11, 2024 - 12:15 p.m.

CVE-2024-35210

2024-06-1112:15:17
CWE-319
siemens
web.nvd.nist.gov
28
sinec traffic analyzer
vulnerability
web server
hsts
downgrade attacks
confidential information

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS4

6.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:N/VI:L/SI:N/VA:N/SA:N

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

32.6%

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information.

Affected configurations

Nvd
Node
siemenssinec_traffic_analyzerRange<1.2
VendorProductVersionCPE
siemenssinec_traffic_analyzer*cpe:2.3:a:siemens:sinec_traffic_analyzer:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "SINEC Traffic Analyzer",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V1.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS4

6.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:N/VI:L/SI:N/VA:N/SA:N

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

32.6%

Related for CVE-2024-35210