Cryptographic Timing Side-Channel Vulnerability in OMICRON StationScout
CVE-2026-16731

8.3HIGH

What is CVE-2026-16731?

OMICRON StationScout versions prior to 3.05 contain a significant cryptographic timing side-channel vulnerability that affects the backend authentication mechanism. This flaw potentially enables an unauthenticated attacker to forge valid authentication credentials, thus bypassing both authentication and authorization processes. By exploiting this vulnerability, an attacker can impersonate legitimate clients, gaining unauthorized full access to system configurations. This access allows for the modification, reset, or unauthorized alteration of system parameters and can lead to the injection of malicious network traffic into the connected network, posing severe security risks.

Affected Version(s)

OMICRON StationScout 0 < 3.05

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.