Siemens SINEC Security Monitor Confidential Information Disclosure Vulnerability
Vulnerability
A vulnerability exists in Siemens SINEC Security Monitor in all versions prior to 4.9.0, allowing the application to unintentionally expose confidential information through metadata and files. This information includes details about contributors and email addresses, which can be accessed on the SSM Server.
Impact
Exploitation of this vulnerability leads to unauthorized disclosure of sensitive information, including contributor details and email addresses, via metadata and files on the SSM Server.
Remediation
Users are advised to update SINEC Security Monitor to version 4.9.0 or later. For more information, visit the Siemens Industry Support page.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
