A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data stored in the local cache.
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sinec_traffic_analyzer | Siemens | * | 2.0 (excluding) |