CVE-2024-23816

A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions < V4.3), Location Intelligence Perpetual Small (9DE5110-8CA11-1AX0) (All versions < V4.3), Location Intelligence SUS Large (9DE5110-8CA13-1BX0) (All versions < V4.3), Location Intelligence SUS Medium (9DE5110-8CA12-1BX0) (All versions < V4.3), Location Intelligence SUS Non-Prod (9DE5110-8CA10-1BX0) (All versions < V4.3), Location Intelligence SUS Small (9DE5110-8CA11-1BX0) (All versions < V4.3). Affected products use a hard-coded secret value for the computation of a Keyed-Hash Message Authentication Code. This could allow an unauthenticated remote attacker to gain full administrative access to the application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:location_intelligence:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:58

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-580228.html - Vendor Advisory () https://cert-portal.siemens.com/productcert/html/ssa-580228.html - Vendor Advisory

22 Oct 2024, 13:10

Type Values Removed Values Added
First Time Siemens
Siemens location Intelligence
CPE cpe:2.3:a:siemens:location_intelligence:*:*:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-580228.html - () https://cert-portal.siemens.com/productcert/html/ssa-580228.html - Vendor Advisory

13 Feb 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-13 09:15

Updated : 2024-11-21 08:58


NVD link : CVE-2024-23816

Mitre link : CVE-2024-23816

CVE.ORG link : CVE-2024-23816


JSON object : View

Products Affected

siemens

  • location_intelligence
CWE
CWE-798

Use of Hard-coded Credentials