CVE-2024-41986 PUBLISHED

Assigner: siemens
Reserved: 25.07.2024 Published: 12.08.2025 Updated: 12.08.2025

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application support insecure TLS 1.0 and 1.1 protocol. An attacker could achieve a man-in-the-middle attack and compromise confidentiality and integrity of data.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.1

Product Status

Vendor Siemens
Product SmartClient modules Opcenter QL Home (SC)
Versions Default: unknown
  • affected from V13.2 to V2506 (excl.)
Vendor Siemens
Product SOA Audit
Versions Default: unknown
  • affected from V13.2 to V2506 (excl.)
Vendor Siemens
Product SOA Cockpit
Versions Default: unknown
  • affected from V13.2 to V2506 (excl.)

References

Problem Types

  • CWE-327: Use of a Broken or Risky Cryptographic Algorithm CWE