Siemens Opcenter Quality
cpe:2.3:a:siemens:opcenter_quality:*:*:*:*:*:*:*
- >= V13.2, < V2506
A vulnerability exists in Siemens Opcenter Quality SmartClient modules, specifically in Opcenter QL Home (SC), SOA Audit, and SOA Cockpit, all versions from 13.2 up to but not including 2506. The vulnerability arises because the application improperly manages errors when trying to access unavailable resources, which can lead to unintended exposure of system applications.
Exploitation of this vulnerability could result in unauthorized exposure of system applications.
Users are advised to update to the latest version of Siemens Opcenter Quality. Specific hardening measures include securing the operating system and IIS, hiding the IIS version, limiting file access to only necessary extensions, and disabling unsecure protocols such as SSL v2, SSL v3, TLS 1.0, and TLS 1.1. Following the general security recommendations and the product's security concept is also recommended.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.