CVE-2024-41980 PUBLISHED

Assigner: siemens
Reserved: 25.07.2024 Published: 12.08.2025 Updated: 12.08.2025

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application do not encrypt the communication in LDAP interface by default. This could allow an authenticated attacker to gain unauthorized access to sensitive information.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2

Product Status

Vendor Siemens
Product SmartClient modules Opcenter QL Home (SC)
Versions Default: unknown
  • affected from V13.2 to V2506 (excl.)
Vendor Siemens
Product SOA Audit
Versions Default: unknown
  • affected from V13.2 to V2506 (excl.)
Vendor Siemens
Product SOA Cockpit
Versions Default: unknown
  • affected from V13.2 to V2506 (excl.)

References

Problem Types

  • CWE-311: Missing Encryption of Sensitive Data CWE