Vulnerability in SINEC Traffic Analyzer Web Server Due to HSTS Non-Compliance
CVE-2024-35210

5.1MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 June 2024

Summary

The SINEC Traffic Analyzer, specifically version 6GK8822-1BG01-0BA0, is susceptible to a significant vulnerability due to its web server's failure to enforce HTTP Strict Transport Security (HSTS). This oversight may permit attackers to execute downgrade attacks, compromising the confidentiality of sensitive information. The vulnerability affects all versions of the product prior to V1.2, necessitating immediate attention by users to ensure their systems remain secure against potential threats. For more detailed information, visit the official reference page.

Affected Version(s)

SINEC Traffic Analyzer 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.