CVE-2024-41985

LOW

Siemens Opcenter Quality - Insufficient Session Expiration

Title source: rule
STIX 2.1

Description

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not expire the session without logout. This could allow an attacker to get unauthorized access if the session is left idle.

Scores

CVSS v3 2.6
EPSS 0.0003
EPSS Percentile 8.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (1)
siemens/opcenter_quality 13.2
Published Aug 12, 2025
Tracked Since Feb 18, 2026