Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-41279 | A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.3.1-1). Affected components do not properly validate the device tokens. This could allow an unauthenticated remote attacker to impersonate other devices onboarded to the system. |
Tue, 10 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens industrial Edge Management Pro Siemens industrial Edge Management Virtual |
|
| CPEs | cpe:2.3:a:siemens:industrial_edge_management_pro:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:industrial_edge_management_virtual:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Siemens
Siemens industrial Edge Management Pro Siemens industrial Edge Management Virtual |
|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.3.1-1). Affected components do not properly validate the device tokens. This could allow an unauthenticated remote attacker to impersonate other devices onboarded to the system. | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-09-10T14:07:02.300Z
Reserved: 2024-08-21T10:23:28.282Z
Link: CVE-2024-45032
Updated: 2024-09-10T14:06:43.595Z
Status : Deferred
Published: 2024-09-10T10:15:13.407
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-45032
No data.
OpenCVE Enrichment
No data.
EUVD