A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions < V4.3), Location Intelligence Perpetual Small (9DE5110-8CA11-1AX0) (All versions < V4.3), Location Intelligence SUS Large (9DE5110-8CA13-1BX0) (All versions < V4.3), Location Intelligence SUS Medium (9DE5110-8CA12-1BX0) (All versions < V4.3), Location Intelligence SUS Non-Prod (9DE5110-8CA10-1BX0) (All versions < V4.3), Location Intelligence SUS Small (9DE5110-8CA11-1BX0) (All versions < V4.3). Affected products use a hard-coded secret value for the computation of a Keyed-Hash Message Authentication Code. This could allow an unauthenticated remote attacker to gain full administrative access to the application.
History

Tue, 22 Oct 2024 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens location Intelligence
CPEs cpe:2.3:a:siemens:location_intelligence:*:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens location Intelligence

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-02-13T09:00:27.125Z

Updated: 2024-08-01T23:13:08.454Z

Reserved: 2024-01-22T17:44:56.763Z

Link: CVE-2024-23816

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2024-02-13T09:15:50.343

Modified: 2024-11-21T08:58:28.797

Link: CVE-2024-23816

cve-icon Redhat

No data.