CVE Vulnerabilities

CVE-2024-41906

Use of Cache Containing Sensitive Information

Published: Aug 13, 2024 | Modified: Aug 14, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data stored in the local cache.

Weakness

The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Sinec_traffic_analyzer Siemens * 2.0 (excluding)

Potential Mitigations

References