PT-2024-7880 · Siemens · Industrial Edge Management+1

Published

2024-08-21

·

Updated

2024-09-14

·

CVE-2024-45032

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Industrial Edge Management Pro versions prior to V1.9.5 Industrial Edge Management Virtual versions prior to V2.3.1-1
Description A vulnerability has been identified in the affected components of Industrial Edge Management, which do not properly validate device tokens. This could allow an unauthenticated remote attacker to impersonate other devices onboarded to the system, potentially bypassing security restrictions and gaining unauthorized access to protected information.
Recommendations For Industrial Edge Management Pro versions prior to V1.9.5, update to version V1.9.5 or later to resolve the issue. For Industrial Edge Management Virtual versions prior to V2.3.1-1, update to version V2.3.1-1 or later to resolve the issue. As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation until a patch is available.

Fix

IDOR

Weakness Enumeration

Related Identifiers

BDU:2024-09384
CVE-2024-45032

Affected Products

Industrial Edge Management
Industrial Edge Management Virtual