PT-2024-29625 · Unknown · Sinec Traffic Analyzer

Published

2024-08-13

·

Updated

2024-08-14

·

CVE-2024-41906

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SINEC Traffic Analyzer versions prior to V2.0
Description The affected application does not properly handle cacheable HTTP responses in the web service, which could allow an attacker to read and modify data stored in the local cache.
Recommendations For versions prior to V2.0, update to version V2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the web service to minimize the risk of exploitation. Avoid using cacheable HTTP responses in the web service until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-41906

Affected Products

Sinec Traffic Analyzer