CVE-2024-41982

MEDIUM

Siemens Opcenter Quality - Missing Encryption

Title source: rule
STIX 2.1

Description

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not have adequate encryption of sensitive information. This could allow an authenticated attacker to gain access of sensitive information.

Scores

CVSS v3 4.8
EPSS 0.0001
EPSS Percentile 1.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-311
Status published
Products (1)
siemens/opcenter_quality 13.2
Published Aug 12, 2025
Tracked Since Feb 18, 2026