Affected Products Vulnerable to Weak Cipher Attacks
CVE-2024-41681
7.5HIGH
Summary
A vulnerability exists in the Location Intelligence family of products from Siemens, specifically those versions prior to V4.4. This flaw stems from the web server's default configuration, which enables the use of weak ciphers. As a result, an unauthenticated attacker positioned between legitimate clients and the affected device can exploit this weakness to intercept, read, and modify sensitive data transmitted over the connection. Organizations utilizing these products should take immediate steps to secure their web server configurations and eliminate reliance on weak cipher suites to protect against potential data breaches.
Affected Version(s)
Location Intelligence family 0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved