First published: Tue Jun 11 2024(Updated: )
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Sinec Traffic Analyzer | <1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35210 is classified as a high severity vulnerability that can lead to downgrade attacks.
To fix CVE-2024-35210, upgrade the SINEC Traffic Analyzer to version 1.2 or later.
CVE-2024-35210 affects all versions of SINEC Traffic Analyzer prior to version 1.2.
CVE-2024-35210 can enable downgrade attacks, which may expose confidential information.
Yes, CVE-2024-35210 is related to the web server not enforcing HTTP Strict Transport Security (HSTS).