CVE-2024-41986: Medium severity SmartClient Opcenter QL Home vulnerability
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application support insecure TLS 1.0 and 1.1 protocol. An attacker could achieve a man-in-the-middle attack and compromise confidentiality and integrity of data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41986?
CVE-2024-41986 is classified as a high-severity vulnerability due to its potential exploitation of insecure TLS protocols.
How do I fix CVE-2024-41986?
To fix CVE-2024-41986, upgrade your SmartClient applications to a version higher than 2506 which disables TLS 1.0 and 1.1.
What applications are affected by CVE-2024-41986?
CVE-2024-41986 affects SmartClient Opcenter QL Home, SOA Audit, and SOA Cockpit all versions between 13.2 and 2506.
What type of attack could exploit CVE-2024-41986?
An attacker could exploit CVE-2024-41986 through man-in-the-middle attacks by leveraging insecure TLS 1.0 and 1.1 protocols.
Is there a specific version of SmartClient that is safe from CVE-2024-41986?
Yes, any version of SmartClient above 2506 is considered safe from CVE-2024-41986 as it no longer supports TLS 1.0 and 1.1.