ICSA-25-226-06: Siemens Opcenter Quality
CISA advisory · released 2025-08-12
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 1, 2025-08-12 (final)
CISA's summary
Summary: The Opcenter Quality is affected by multiple vulnerabilities in the SmartClient modules Opcenter QL Home (SC), SOA Audit and SOA Cockpit. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | SmartClient modules Opcenter QL Home (SC) | vers:intdot/>=13.2|<2506 |
| Siemens | SOA Audit | vers:intdot/>=13.2|<2506 |
| Siemens | SOA Cockpit | vers:intdot/>=13.2|<2506 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2024-41979 — CVE-2024-41979 · CWE-863
The affected application does not enforce mandatory authorization on some functionality level at server side. This could allow an authenticated attacker to gain complete access of the application.
- CVE-2024-41980 — CVE-2024-41980 · CWE-311
The affected application do not encrypt the communication in LDAP interface by default. This could allow an authenticated attacker to gain unauthorized access to sensitive information.
- CVE-2024-41982 — CVE-2024-41982 · CWE-311
The affected application does not have adequate encryption of sensitive information. This could allow an authenticated attacker to gain access of sensitive information.
- CVE-2024-41983 — CVE-2024-41983 · CWE-209
The affected application displays SQL statement in the error messages encountered during the generation of reports using Cockpit tool.
- CVE-2024-41984 — CVE-2024-41984 · CWE-209
The affected application improperly handles error while accessing an inaccessible resource leading to exposing the system applications.
- CVE-2024-41985 — CVE-2024-41985 · CWE-613
The affected application does not expire the session without logout. This could allow an attacker to get unauthorized access if the session is left idle.
- CVE-2024-41986 — CVE-2024-41986 · CWE-327
The affected application support insecure TLS 1.0 and 1.1 protocol. An attacker could achieve a man-in-the-middle attack and compromise confidentiality and integrity of data.
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reporting these vulnerabilities to CISA.
The advisory's legal notice
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.