Session Management Flaw in SIMATIC PCS neo and Related Siemens Products
CVE-2024-45386
8.7HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 11 February 2025
What is CVE-2024-45386?
A session management vulnerability exists in multiple Siemens products, including SIMATIC PCS neo. The issue arises from the failure to properly invalidate user sessions following logout. As a result, remote attackers could potentially exploit this flaw by reusing session tokens collected through unauthorized means, thereby gaining access to user accounts and sensitive information even after legitimate users have logged out.
Affected Version(s)
SIMATIC PCS neo V4.0 0
SIMATIC PCS neo V4.1 0
SIMATIC PCS neo V5.0 0