PT-2024-8130 · Siemens · Siemens Sinec Security Monitor

CVE-2024-47565

·

Published

2024-10-08

·

Updated

2024-10-11

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Siemens SINEC Security Monitor versions prior to V4.9.0
Description: A vulnerability has been identified where the affected application does not properly validate that user input complies with a list of allowed values. This could allow an authenticated remote attacker to compromise the integrity of the configuration of the affected application.
Recommendations: For versions prior to V4.9.0, update to version V4.9.0 or later to resolve the issue. As a temporary workaround, consider restricting user input to only allowed values to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09669
CVE-2024-47565

Affected Products

Siemens Sinec Security Monitor