CVE-2024-23816

A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions < V4.3), Location Intelligence Perpetual Small (9DE5110-8CA11-1AX0) (All versions < V4.3), Location Intelligence SUS Large (9DE5110-8CA13-1BX0) (All versions < V4.3), Location Intelligence SUS Medium (9DE5110-8CA12-1BX0) (All versions < V4.3), Location Intelligence SUS Non-Prod (9DE5110-8CA10-1BX0) (All versions < V4.3), Location Intelligence SUS Small (9DE5110-8CA11-1BX0) (All versions < V4.3). Affected products use a hard-coded secret value for the computation of a Keyed-Hash Message Authentication Code. This could allow an unauthenticated remote attacker to gain full administrative access to the application.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:location_intelligence:*:*:*:*:*:*:*:*

History

22 Oct 2024, 13:10

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:location_intelligence:*:*:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-580228.html - () https://cert-portal.siemens.com/productcert/html/ssa-580228.html - Vendor Advisory
First Time Siemens location Intelligence
Siemens

13 Feb 2024, 14:01

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en: Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (Todas las versiones &lt; V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (Todas las versiones &lt; V4.3), Location Intelligence Perpetual Non -Prod (9DE5110-8CA10-1AX0) (todas las versiones &lt; V4.3), Location Intelligence Perpetual Small (9DE5110-8CA11-1AX0) (todas las versiones &lt; V4.3), Location Intelligence SUS Large (9DE5110-8CA13-1BX0) ( Todas las versiones &lt; V4.3), Location Intelligence SUS Medium (9DE5110-8CA12-1BX0) (Todas las versiones &lt; V4.3), Location Intelligence SUS Non-Prod (9DE5110-8CA10-1BX0) (Todas las versiones &lt; V4.3), Location Intelligence SUS Small (9DE5110-8CA11-1BX0) (Todas las versiones &lt; V4.3). Los productos afectados utilizan un valor secreto codificado para el cálculo de un código de autenticación de mensaje hash con clave. Esto podría permitir que un atacante remoto no autenticado obtenga acceso administrativo completo a la aplicación.

13 Feb 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-13 09:15

Updated : 2024-10-22 13:10


NVD link : CVE-2024-23816

Mitre link : CVE-2024-23816

CVE.ORG link : CVE-2024-23816


JSON object : View

Products Affected

siemens

  • location_intelligence
CWE
CWE-798

Use of Hard-coded Credentials