Unauthenticated Remote Attacker Could Impersonate Other Devices via Validation Vulnerability
CVE-2024-45032

10CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
10 September 2024

Summary

A vulnerability in Siemens Industrial Edge Management products has been identified where certain versions do not adequately validate device tokens. This flaw can be exploited by remote attackers who could assume the identities of legitimate devices within the system, potentially compromising the integrity and security of the environment. The vulnerability affects all versions of Industrial Edge Management Pro prior to V1.9.5 and all versions of Industrial Edge Management Virtual before V2.3.1-1. Organizations utilizing these products should assess their security measures and implement available patches to mitigate risks associated with this issue.

Affected Version(s)

Industrial Edge Management Pro 0

Industrial Edge Management Virtual 0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.