ZDI-CAN-20492: ZDI-24-353: Softing edgeConnector Siemens Cleartext Transmission of Credentials Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2024-0860.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20492?
The severity of ZDI-CAN-20492 is rated at 8.0 according to CVSS.
How can I fix ZDI-CAN-20492?
To fix ZDI-CAN-20492, ensure that you apply the latest security patches provided by Softing for edgeConnector Siemens.
Who is affected by ZDI-CAN-20492?
ZDI-CAN-20492 affects installations of Softing edgeConnector Siemens that have not implemented the necessary security measures.
Is authentication required to exploit ZDI-CAN-20492?
No, authentication is not required to exploit ZDI-CAN-20492, making it particularly concerning.
What type of attackers can exploit ZDI-CAN-20492?
ZDI-CAN-20492 can be exploited by network-adjacent attackers.