HIGH🇬🇧 English

CVE-2024-41979

CVSS 7.5v4.0pub. 2025-08-12upd. 2025-10-23

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not enforce mandatory authorization on some functionality level at server side. This could allow an authenticated attacker to gain complete access of the application.

oryginał EN
CVSS Vector
CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Siemens Opcenter Quality

    APP
    Siemens
    13.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2021-27389CRITICAL9.8PL ✓ten sam produkt

Siemens Opcenter Quality / QMS Automotive — ujawniony prywatny klucz podpisu

CVE-2023-46281HIGH7.1ten sam produkt

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality ...

CVE-2023-46283HIGH7.5ten sam produkt

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality ...

CVE-2023-46282HIGH7.1ten sam produkt

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality ...

CVE-2023-46284HIGH7.5ten sam produkt

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality ...