ICSA-24-165-13: Siemens SINEC Traffic Analyzer
CISA advisory · released 2024-06-11
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 3, 2025-05-06 (final)
CISA's summary
Summary: SINEC Traffic Analyzer before V1.2 is affected by multiple vulnerabilities. Siemens has released a new version for SINEC Traffic Analyzer and recommends to update to the latest version.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) | <V1.2 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2022-41742 — CVE-2022-41742 · CWE-787
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
- CVE-2024-35206 — CVE-2024-35206 · CWE-613
The affected application does not expire the session. This could allow an attacker to get unauthorized access.
- CVE-2024-35207 — CVE-2024-35207 · CWE-352
The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.
- CVE-2024-35208 — CVE-2024-35208 · CWE-522
The affected web server stored the password in cleartext. This could allow attacker in a privileged position to obtain access passwords.
- CVE-2024-35209 — CVE-2024-35209 · CWE-749
The affected web server is allowing HTTP methods like PUT and Delete. This could allow an attacker to modify unauthorized files.
- CVE-2024-35210 — CVE-2024-35210 · CWE-319
The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information.
- CVE-2024-35211 — CVE-2024-35211 · CWE-614
The affected web server, after a successful login, sets the session cookie on the browser, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”).
- CVE-2024-35212 — CVE-2024-35212 · CWE-20
The affected application lacks input validation due to which an attacker can gain access to the Database entries.
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reporting these vulnerabilities to CISA.
The advisory's legal notice
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.