Siemens Opcenter QL Home
cpe:2.3:a:siemens:opcenter_quality:*:*:*:*:*:*:*
- >= V13.2, < V2506
A session management vulnerability has been identified in Siemens Opcenter Quality SmartClient modules, specifically in Opcenter QL Home (SC), SOA Audit, and SOA Cockpit, all versions prior to V2506. The vulnerability arises because the application does not properly expire sessions after a period of inactivity, potentially allowing unauthorized access if a session is left idle.
Exploitation of this vulnerability could lead to unauthorized access to the application by taking advantage of an idle session.
Siemens has released new versions for the affected products and recommends updating to the latest versions. Specific workarounds include operating the SmartClient in a secured network and context, following the hardening instructions mentioned in the product's security concept, and ensuring that all users are given the least privileges required.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.