PT-2024-5125 · Sicam Egs+1 · Sicam Egs+4
Jan Kaestle
·
Published
2024-07-22
·
Updated
2024-11-27
·
CVE-2024-37998
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
CPCI85 Central Processing/Communication versions prior to V5.40
SICORE Base system versions prior to V1.4.0
SICAM CP-8031, CP-8050, SICAM EGS (affected versions not specified)
Description:
The issue is related to the lack of necessary authentication checks when resetting passwords, which could allow a remote attacker to gain full control over the device. Specifically, the password of administrative accounts can be reset without knowing the current password if auto-login is enabled. This could enable an unauthorized attacker to obtain administrative access to the affected applications.
Recommendations:
For CPCI85 Central Processing/Communication versions prior to V5.40, update to version V5.40 or later to resolve the issue.
For SICORE Base system versions prior to V1.4.0, update to version V1.4.0 or later to resolve the issue.
For SICAM CP-8031, CP-8050, SICAM EGS, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cpci85 Central Processing/Communication
Sicam Cp-8031
Sicam Cp-8050
Sicam Egs
Sicore Base System