PT-2024-8130 · Siemens · Siemens Sinec Security Monitor

Published

2024-10-08

·

Updated

2024-10-11

·

CVE-2024-47565

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Siemens SINEC Security Monitor versions prior to V4.9.0
Description: A vulnerability has been identified where the affected application does not properly validate that user input complies with a list of allowed values. This could allow an authenticated remote attacker to compromise the integrity of the configuration of the affected application.
Recommendations: For versions prior to V4.9.0, update to version V4.9.0 or later to resolve the issue. As a temporary workaround, consider restricting user input to only allowed values to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-09669
CVE-2024-47565

Affected Products

Siemens Sinec Security Monitor