CVE-2024-23816: Critical severity Siemens Location Intelligence vulnerability
A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions < V4.3), Location Intelligence Perpetual Small (9DE5110-8CA11-1AX0) (All versions < V4.3), Location Intelligence SUS Large (9DE5110-8CA13-1BX0) (All versions < V4.3), Location Intelligence SUS Medium (9DE5110-8CA12-1BX0) (All versions < V4.3), Location Intelligence SUS Non-Prod (9DE5110-8CA10-1BX0) (All versions < V4.3), Location Intelligence SUS Small (9DE5110-8CA11-1BX0) (All versions < V4.3). Affected products use a hard-coded secret value for the computation of a Keyed-Hash Message Authentication Code. This could allow an unauthenticated remote attacker to gain full administrative access to the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Location Intelligence Perpetual Largeto a version that resolves this vulnerability.Fixed in V4.3 - Upgrade
Upgrade
Location Intelligence Perpetual Mediumto a version that resolves this vulnerability.Fixed in V4.3 - Upgrade
Upgrade
Location Intelligence Perpetual Non-Prodto a version that resolves this vulnerability.Fixed in V4.3 - Upgrade
Upgrade
Location Intelligence Perpetual Smallto a version that resolves this vulnerability.Fixed in V4.3 - Upgrade
Upgrade
Location Intelligence SUS Largeto a version that resolves this vulnerability.Fixed in V4.3 - Upgrade
Upgrade
Location Intelligence SUS Mediumto a version that resolves this vulnerability.Fixed in V4.3 - Upgrade
Upgrade
Location Intelligence SUS Non-Prodto a version that resolves this vulnerability.Fixed in V4.3 - Upgrade
Upgrade
Location Intelligence SUS Smallto a version that resolves this vulnerability.Fixed in V4.3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23816?
The severity of CVE-2024-23816 has not been publicly assigned, but it impacts multiple versions of Siemens Location Intelligence.
How do I fix CVE-2024-23816?
To fix CVE-2024-23816, upgrade Siemens Location Intelligence to version 4.3 or later.
What products are affected by CVE-2024-23816?
CVE-2024-23816 affects all versions of Siemens Location Intelligence prior to version 4.3.
Is CVE-2024-23816 a remote vulnerability?
CVE-2024-23816 is a local vulnerability that can potentially be exploited if the attacker has access to the affected software.
What are the potential risks of CVE-2024-23816?
The potential risks of CVE-2024-23816 include unauthorized access or manipulation of location data within affected software.