Description
OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients.
An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters.
Published: 2026-08-06
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a cryptographic timing side‑channel that lets an attacker with no prior authentication forge valid credentials and bypass the back‑end authentication and authorization mechanisms. By exploiting this flaw the attacker can impersonate a legitimate client and gain full access to the system configuration, enabling modification, reset, or unauthorized alteration of critical parameters.

Affected Systems

The affected product is OMICRON electronics GmbH StationGuard firmware before version 4.10. No other versions or vendors are listed in the current data.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity, and the absence of an EPSS rating indicates that no recent public exploitation data is available. The flaw is listed as not being part of the CISA KEV catalog, so it is not known to be actively exploited in the wild. Based on the description it is inferred that the attack vector is remote, as an unauthenticated attacker can send authentication requests to the backend and observe timing differences to build valid credentials.

Generated by OpenCVE AI on August 6, 2026 at 16:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OMICRON StationGuard to version 4.10 or later to address the timing side‑channel flaw.
  • If an immediate update is not possible, restrict network access to the device by placing it behind a firewall and limiting inbound connections to trusted IP addresses only.
  • Monitor authentication traffic for anomalous timing patterns or repeated short‑duration attempts and alert on potential side‑channel exploitation.

Generated by OpenCVE AI on August 6, 2026 at 16:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters.
Title Authentication and authorization bypass via cryptographic timing side-channel attack in StationGuard
First Time appeared Omicron Electronics Gmbh
Omicron Electronics Gmbh omicron Stationguard
Weaknesses CWE-208
CPEs cpe:2.3:a:omicron_electronics_gmbh:omicron_stationguard:*:*:*:*:*:*:*:*
Vendors & Products Omicron Electronics Gmbh
Omicron Electronics Gmbh omicron Stationguard
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U'}


Subscriptions

Omicron Electronics Gmbh Omicron Stationguard
cve-icon MITRE

Status: PUBLISHED

Assigner: OMICRON

Published:

Updated: 2026-08-06T14:44:35.820Z

Reserved: 2026-07-20T15:44:30.887Z

Link: CVE-2026-16315

cve-icon Vulnrichment

Updated: 2026-08-06T14:44:32.240Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:30:04Z

Weaknesses
  • CWE-208

    Observable Timing Discrepancy