Unauthenticated Remote Attacker Could Impersonate Other Devices via Validation Vulnerability
CVE-2024-45032
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 10 September 2024
Summary
A vulnerability in Siemens Industrial Edge Management products has been identified where certain versions do not adequately validate device tokens. This flaw can be exploited by remote attackers who could assume the identities of legitimate devices within the system, potentially compromising the integrity and security of the environment. The vulnerability affects all versions of Industrial Edge Management Pro prior to V1.9.5 and all versions of Industrial Edge Management Virtual before V2.3.1-1. Organizations utilizing these products should assess their security measures and implement available patches to mitigate risks associated with this issue.
Affected Version(s)
Industrial Edge Management Pro 0
Industrial Edge Management Virtual 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved