CVE-2024-35207

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:sinec_traffic_analyzer:*:*:*:*:*:*:*:*

History

06 Aug 2024, 15:02

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (Todas las versiones &lt; V1.2). La interfaz web de los dispositivos afectados es vulnerable a ataques de Cross-Site Request Forgery (CSRF). Al engañar a un usuario víctima autenticado para que haga clic en un enlace malicioso, un atacante podría realizar acciones arbitrarias en el dispositivo en nombre del usuario víctima.
First Time Siemens
Siemens sinec Traffic Analyzer
References () https://cert-portal.siemens.com/productcert/html/ssa-196737.html - () https://cert-portal.siemens.com/productcert/html/ssa-196737.html - Patch, Vendor Advisory
CPE cpe:2.3:a:siemens:sinec_traffic_analyzer:*:*:*:*:*:*:*:*

11 Jun 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-11 12:15

Updated : 2024-08-06 15:02


NVD link : CVE-2024-35207

Mitre link : CVE-2024-35207

CVE.ORG link : CVE-2024-35207


JSON object : View

Products Affected

siemens

  • sinec_traffic_analyzer
CWE
CWE-352

Cross-Site Request Forgery (CSRF)