CVE-2024-41985 PUBLISHED

Assigner: siemens
Reserved: 25.07.2024 Published: 12.08.2025 Updated: 12.08.2025

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not expire the session without logout. This could allow an attacker to get unauthorized access if the session is left idle.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2.1

Product Status

Vendor Siemens
Product SmartClient modules Opcenter QL Home (SC)
Versions Default: unknown
  • affected from V13.2 to V2506 (excl.)
Vendor Siemens
Product SOA Audit
Versions Default: unknown
  • affected from V13.2 to V2506 (excl.)
Vendor Siemens
Product SOA Cockpit
Versions Default: unknown
  • affected from V13.2 to V2506 (excl.)

References

Problem Types

  • CWE-613: Insufficient Session Expiration CWE