SINEC Traffic Analyzer <v2.0 Missing HTTP Security Headers Clickjacking Risk
CVE-2024-41907 Published on August 13, 2024

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to clickjacking attack.

NVD

Weakness Type

Improperly Implemented Security Check for Standard

The software does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.


Products Associated with CVE-2024-41907

Want to know whenever a new CVE is published for Siemens Sinec Traffic Analyzer? stack.watch will email you.

 

Affected Versions

Siemens SINEC Traffic Analyzer:

Exploit Probability

EPSS
0.54%
Percentile
67.25%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.