VDB
CVE-2024-41906
CVE-2024-41906
PUBLISHED
CVSS 4.800000190734863 MEDIUM
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data stored in the local cache.
EPSS 0.23% · 12.8th percentile
Risk Scores
CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.23%
12.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SINEC Traffic Analyzer | 0 |
| siemens | sinec_traffic_analyzer | 0 |
Timeline
- Aug 13, 2024 CVE Published
- Aug 13, 2024 EPSS Score
- Aug 13, 2024 PoC Published
- Aug 16, 2024 CVE Updated
- Sep 3, 2024 EPSS Score
- Sep 24, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 15, 2024 EPSS Score
- Nov 6, 2024 EPSS Score
- Nov 27, 2024 EPSS Score
- Dec 19, 2024 EPSS Score
- Jan 9, 2025 EPSS Score
References
- https://cert-portal.siemens.com/productcert/html/ssa-357412.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-784301.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-716317.html url
- https://nvd.nist.gov/vuln/detail/CVE-2024-41906 advisory
- https://cert-portal.siemens.com/productcert/html/ssa-068047.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-720392.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-921449.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-659443.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-417547.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-087301.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-856475.html advisory