Impact
The vulnerability is a cryptographic timing side-channel flaw in the backend authentication of OMICRON StationScout devices. It allows an unauthenticated attacker to forge valid authentication credentials, bypass both authentication and authorization, and impersonate legitimate clients. The exploitation of this flaw can give the attacker unrestricted access to the system configuration, enabling modification, reset, or unauthorized alterations of system parameters, and potentially allowing injection of network traffic into the connected network. The weakness is classified as CWE‑208.
Affected Systems
OMICRON electronics GmbH OMICRON StationScout devices running a firmware version earlier than 3.05 are affected.
Risk and Exploitability
The CVSS score is 8.3, indicating a high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, network‑based: an attacker can send crafted requests to the authentication service and observe timing variations to forge credentials. No user interaction or privileged access is required to exploit the flaw.
OpenCVE Enrichment