Impact
A flaw in Opcenter X allows an attacker to the platform accepts without validating the signing algorithm. The result is a complete compromise of authentication controls: anyone can impersonate any user, including administrators, and gain unrestricted access to the application. The vulnerability is classified as CWE‑347 and provides an unconditional path to bypass security checks.
Affected Systems
The issue affects all releases of Siemens Opcenter X prior to version V2604. Users running any of those older versions are vulnerable.
Risk and Exploitability
The CVSS score of 10 indicates catastrophic impact if exploited. Although the EPSS score is below 1%—a low probability of exploitation in the wild—the flaw remains highly dangerous because the attack is remote, unauthenticated, and can be executed from any network location. It is not listed in the CISA KEV catalog, but the severity and the potential for full account takeover demand urgent attention.
OpenCVE Enrichment