VDB

CVE-2024-41906

CVE-2024-41906 PUBLISHED CVSS 4.800000190734863 MEDIUM

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data stored in the local cache.

EPSS 0.36% · 58.1th percentile

Risk Scores

CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.36%
58.1th percentile

Affected Products

VendorProductVersions
SiemensSINEC Traffic Analyzer0
siemenssinec_traffic_analyzer0

Timeline

  • Aug 13, 2024 CVE Published
  • Aug 13, 2024 EPSS Score
  • Aug 13, 2024 PoC Published
  • Aug 14, 2024 CVE Updated
  • Sep 3, 2024 EPSS Score
  • Sep 24, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 14, 2024 EPSS Score
  • Nov 4, 2024 EPSS Score
  • Nov 25, 2024 EPSS Score
  • Dec 17, 2024 EPSS Score
  • Jan 7, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›