The affected products could allow an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authentication.
The vulnerability (CWE-547 — Use of Hard-coded, Security-relevant Constants) consists of the ability for an attacker to generate forged JWT tokens without prior authentication. An attacker can construct an appropriately crafted JWT token that will be accepted by the vulnerable system as valid. Consequently, the JWT-based authentication mechanism is completely bypassed.
An attacker gains unauthorized access to the system, potentially taking control of protected resources and data. This can lead to violations of system confidentiality and integrity without requiring any authentication credentials.
Manufacturer-provided patches should be applied according to the references. Detailed information regarding updates is available in the CISA ICS-CERT advisory at: https://www.cisa.gov/news-events/ics-advisories/icsa-25-175-07
Versions specified in manufacturer references (details in CISA ICS-CERT advisory: ICSA-25-175-07)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X