VDB

CVE-2024-41904

CVE-2024-41904 PUBLISHED CVSS 7.5 HIGH

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated attacker to conduct brute force attacks against legitimate user credentials or keys.

EPSS 0.59% · 69.7th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.59%
69.7th percentile

Affected Products

VendorProductVersions
siemenssinec_traffic_analyzer0
SiemensSINEC Traffic Analyzer0
siemenssinec_traffic_analyzer0

Timeline

  • Aug 13, 2024 CVE Published
  • Aug 13, 2024 EPSS Score
  • Aug 13, 2024 PoC Published
  • Sep 3, 2024 EPSS Score
  • Sep 24, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 14, 2024 EPSS Score
  • Nov 4, 2024 EPSS Score
  • Nov 25, 2024 EPSS Score
  • Dec 17, 2024 EPSS Score
  • Jan 7, 2025 EPSS Score
  • Jan 28, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›