SSA-342348 PUBLISHED CVSS 8.800000190734863 HIGH

Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
SiemensSIRIUS Safety ES V19 (TIA Portal)
SiemensSIMATIC PCS neo V4.0
SiemensTIA Administrator
SiemensSIRIUS Soft Starter ES V19 (TIA Portal)
SiemensSIMATIC PCS neo V4.1
SiemensSIMATIC PCS neo V5.0
SiemensSIMOCODE ES V19

Timeline

References

Open in Interactive Console →