Clickjacking Vulnerability in SINEC Traffic Analyzer

CVE-2024-41907

5.4MEDIUM

Key Information

Vendor
Siemens
Status
Sinec Traffic Analyzer
Vendor
CVE Published:
13 August 2024

Summary

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to clickjacking attack.

Affected Version(s)

SINEC Traffic Analyzer < 0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.