First published: Tue Jun 11 2024(Updated: )
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password in cleartext. This could allow attacker in a privileged position to obtain access passwords.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Sinec Traffic Analyzer | <1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35208 is considered a high severity vulnerability due to the storage of passwords in cleartext.
To fix CVE-2024-35208, upgrade to Siemens SINEC Traffic Analyzer version 1.2 or later.
CVE-2024-35208 affects all versions of Siemens SINEC Traffic Analyzer prior to version 1.2.
An attacker exploiting CVE-2024-35208 could retrieve access passwords stored in cleartext on the affected server.
There are no documented workarounds for CVE-2024-35208; upgrading to the latest version is recommended.