PT-2024-4581 · Unknown · Sinec Traffic Analyzer

Published

2024-06-11

·

Updated

2024-08-06

·

CVE-2024-35210

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: SINEC Traffic Analyzer versions prior to V1.2
Description: A vulnerability has been identified in the web server of SINEC Traffic Analyzer, where it is not enforcing HSTS. This could allow an attacker to perform downgrade attacks, exposing confidential information. The vulnerability is related to the transmission of data in plain text, which can be exploited by a remote attacker to execute a downgrade attack.
Recommendations: For versions prior to V1.2, consider enforcing HSTS on the web server to prevent downgrade attacks. As a temporary workaround, restrict access to sensitive information until a patch is available.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2024-05087
CVE-2024-35210

Affected Products

Sinec Traffic Analyzer