A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not enforce mandatory authorization on some functionality level at server side. This could allow an authenticated attacker to gain complete access of the application.
History

Tue, 12 Aug 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens smartclient Modules
Siemens soa Audit
Siemens soa Cockpit
Vendors & Products Siemens
Siemens smartclient Modules
Siemens soa Audit
Siemens soa Cockpit

Tue, 12 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Aug 2025 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not enforce mandatory authorization on some functionality level at server side. This could allow an authenticated attacker to gain complete access of the application.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2025-08-12T11:16:34.660Z

Updated: 2025-08-12T15:54:33.400Z

Reserved: 2024-07-25T12:46:30.321Z

Link: CVE-2024-41979

cve-icon Vulnrichment

Updated: 2025-08-12T15:54:28.966Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-12T12:15:31.980

Modified: 2025-08-12T14:25:33.177

Link: CVE-2024-41979

cve-icon Redhat

No data.