VDB
CVE-2024-41906
CVE-2024-41906
PUBLISHED
CVSS 4.800000190734863 MEDIUM
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data stored in the local cache.
EPSS 0.36% · 58.1th percentile
Risk Scores
CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.36%
58.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SINEC Traffic Analyzer | 0 |
| siemens | sinec_traffic_analyzer | 0 |
Exploit Intelligence
- CIRCL seen: CVE-2024-41906 (circl-sighting)
- https://cert-portal.siemens.com/productcert/html/ssa-716317.html (circl)
Timeline
- Aug 13, 2024 CVE Published
- Aug 13, 2024 EPSS Score
- Aug 13, 2024 PoC Published
- Aug 14, 2024 CVE Updated
- Sep 3, 2024 EPSS Score
- Sep 24, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 14, 2024 EPSS Score
- Nov 4, 2024 EPSS Score
- Nov 25, 2024 EPSS Score
- Dec 17, 2024 EPSS Score
- Jan 7, 2025 EPSS Score
References
- https://cert-portal.siemens.com/productcert/html/ssa-856475.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-357412.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-720392.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-921449.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-068047.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-784301.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-716317.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-659443.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-087301.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-417547.html advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-41906 advisory