CVE-2026-16315: Authentication and authorization bypass via cryptographic timing side-channel attack in StationGuard
OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OMICRON StationGuardto a version that resolves this vulnerability.Fixed in 4.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16315?
CVE-2026-16315 has a severity rating of high (8.7).
How do I fix CVE-2026-16315?
To mitigate CVE-2026-16315, upgrade to StationGuard version 4.10 or later.
What is the risk associated with CVE-2026-16315?
CVE-2026-16315 presents a risk score of 64, indicating a significant security concern.
What kind of attack does CVE-2026-16315 allow?
CVE-2026-16315 allows an unauthenticated attacker to conduct a cryptographic timing side-channel attack to bypass authentication and authorization.
Who is affected by CVE-2026-16315?
Users of OMICRON StationGuard versions prior to 4.10 are affected by CVE-2026-16315.