PT-2024-5125 · Sicam Egs+1 · Sicam Egs+4

Jan Kaestle

·

Published

2024-07-22

·

Updated

2024-11-27

·

CVE-2024-37998

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: CPCI85 Central Processing/Communication versions prior to V5.40 SICORE Base system versions prior to V1.4.0 SICAM CP-8031, CP-8050, SICAM EGS (affected versions not specified)
Description: The issue is related to the lack of necessary authentication checks when resetting passwords, which could allow a remote attacker to gain full control over the device. Specifically, the password of administrative accounts can be reset without knowing the current password if auto-login is enabled. This could enable an unauthorized attacker to obtain administrative access to the affected applications.
Recommendations: For CPCI85 Central Processing/Communication versions prior to V5.40, update to version V5.40 or later to resolve the issue. For SICORE Base system versions prior to V1.4.0, update to version V1.4.0 or later to resolve the issue. For SICAM CP-8031, CP-8050, SICAM EGS, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-05672
CVE-2024-37998

Affected Products

Cpci85 Central Processing/Communication
Sicam Cp-8031
Sicam Cp-8050
Sicam Egs
Sicore Base System