A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). An attacker with network access to the integrated web server on port 80/tcp could obtain the session ID of an active user session. A user must be logged in to the web interface. Siemens recommends to use the integrated webserver on port 80/tcp only in trusted networks.
This category identifies Software Fault Patterns (SFPs) within the Information Leak cluster (SFP23).
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/100560 | third party advisory vdb entry |
https://cert-portal.siemens.com/productcert/pdf/ssa-087240.pdf | patch vendor advisory |