Description
OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients.
An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters or injecting network traffic into the connected network.
Published: 2026-08-06
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a cryptographic timing side-channel flaw in the backend authentication of OMICRON StationScout devices. It allows an unauthenticated attacker to forge valid authentication credentials, bypass both authentication and authorization, and impersonate legitimate clients. The exploitation of this flaw can give the attacker unrestricted access to the system configuration, enabling modification, reset, or unauthorized alterations of system parameters, and potentially allowing injection of network traffic into the connected network. The weakness is classified as CWE‑208.

Affected Systems

OMICRON electronics GmbH OMICRON StationScout devices running a firmware version earlier than 3.05 are affected.

Risk and Exploitability

The CVSS score is 8.3, indicating a high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, network‑based: an attacker can send crafted requests to the authentication service and observe timing variations to forge credentials. No user interaction or privileged access is required to exploit the flaw.

Generated by OpenCVE AI on August 6, 2026 at 16:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update OMICRON StationScout to version 3.05 or later, which fixes the timing side‑channel vulnerability.
  • If an immediate upgrade is not feasible, restrict external access to the device’s authentication interface and enforce network segmentation to block unauthenticated requests from the public network.
  • After applying the patch or hardening, validate that forged authentication attempts no longer succeed and monitor logs for any abnormal authentication activity.

Generated by OpenCVE AI on August 6, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters or injecting network traffic into the connected network.
Title Authentication and authorization bypass via cryptographic timing side-channel attack in StationScout
First Time appeared Omicron Electronics Gmbh
Omicron Electronics Gmbh omicron Stationscout
Weaknesses CWE-208
CPEs cpe:2.3:a:omicron_electronics_gmbh:omicron_stationscout:*:*:*:*:*:*:*:*
Vendors & Products Omicron Electronics Gmbh
Omicron Electronics Gmbh omicron Stationscout
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/S:P'}


Subscriptions

Omicron Electronics Gmbh Omicron Stationscout
cve-icon MITRE

Status: PUBLISHED

Assigner: OMICRON

Published:

Updated: 2026-08-06T14:43:50.431Z

Reserved: 2026-07-23T06:38:04.008Z

Link: CVE-2026-16731

cve-icon Vulnrichment

Updated: 2026-08-06T14:43:47.796Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:30:04Z

Weaknesses
  • CWE-208

    Observable Timing Discrepancy