CVE-2024-41903

MEDIUM

SINEC Traffic Analyzer < 2.0 - Unauthorized Filesystem Modification via Container Root Mount

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the container's root filesystem with read and write privileges. This could allow an attacker to alter the container's filesystem leading to unauthorized modifications and data corruption.

References (1)

Core 1

Scores

CVSS v3 6.6
EPSS 0.0035
EPSS Percentile 57.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
siemens/sinec_traffic_analyzer < 2.0
Published Aug 13, 2024
Tracked Since Feb 18, 2026