Siemens Sinec Traffic Analyzer vulnerabilities
17 known vulnerabilities affecting siemens/sinec_traffic_analyzer.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH9MEDIUM7LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-40767HIGHCVSS 8.8fixed in 3.0fixed in V3.02025-08-12
CVE-2025-40767 [HIGH] CWE-250 CVE-2025-40767: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker containers without adequate security controls to enforce isolation. This could allow an attacker to gain elevated access, potentially accessing sensitive host system resources.
cvelistv5nvd
CVE-2025-40768HIGHCVSS 7.0fixed in 3.0fixed in V3.02025-08-12
CVE-2025-40768 [HIGH] CWE-200 CVE-2025-40768: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application exposes an internal service port to be accessible from outside the system. This could allow an unauthorized attacker to access the application.
cvelistv5nvd
CVE-2025-40770HIGHCVSS 7.5fixed in 3.0fixed in *2025-08-12
CVE-2025-40770 [HIGH] CWE-300 CVE-2025-40770: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). T
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). The affected application uses a monitoring interface that is not operating in a strictly passive mode. This could allow an attacker to interact with the interface, leading to man-in-the-middle attacks.
cvelistv5nvd
CVE-2025-40769HIGHCVSS 7.5fixed in V3.02025-08-12
CVE-2025-40769 [HIGH] CWE-1164 CVE-2025-40769: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application uses a Content Security Policy that allows unsafe script execution methods. This could allow an attacker to execute unauthorized scripts, potentially leading to cross-site scripting attacks.
cvelistv5nvd
CVE-2025-40766MEDIUMCVSS 6.8fixed in 3.0fixed in V3.02025-08-12
CVE-2025-40766 [MEDIUM] CWE-400 CVE-2025-40766: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker containers without adequate resource and security limitations. This could allow an attacker to perform a denial-of-service (DoS) attack.
cvelistv5nvd
CVE-2024-41904HIGHCVSS 8.7fixed in 2.0fixed in V2.02024-08-13
CVE-2024-41904 [HIGH] CWE-307 CVE-2024-41904: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated attacker to conduct brute force attacks against legitimate user credentials or keys.
cvelistv5nvd
CVE-2024-41905HIGHCVSS 7.6fixed in 2.0fixed in V2.02024-08-13
CVE-2024-41905 [HIGH] CWE-284 CVE-2024-41905: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low privilege's to get access to sensitive information.
cvelistv5nvd
CVE-2024-41903HIGHCVSS 7.5fixed in 2.0fixed in V2.02024-08-13
CVE-2024-41903 [HIGH] CWE-269 CVE-2024-41903: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the container's root filesystem with read and write privileges. This could allow an attacker to alter the container's filesystem leading to unauthorized modifications and data corruption.
cvelistv5nvd
CVE-2024-41906MEDIUMCVSS 6.3fixed in 2.0fixed in V2.02024-08-13
CVE-2024-41906 [MEDIUM] CWE-524 CVE-2024-41906: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data stored in the local cache.
cvelistv5nvd
CVE-2024-41907LOWCVSS 2.1fixed in 2.0fixed in V2.02024-08-13
CVE-2024-41907 [LOW] CWE-358 CVE-2024-41907: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to clickjacking attack.
cvelistv5nvd
CVE-2024-35206HIGHCVSS 8.5fixed in 1.2fixed in V1.22024-06-11
CVE-2024-35206 [HIGH] CWE-613 CVE-2024-35206: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application does not expire the session. This could allow an attacker to get unauthorized access.
cvelistv5nvd
CVE-2024-35207HIGHCVSS 8.5fixed in 1.2fixed in V1.22024-06-11
CVE-2024-35207 [HIGH] CWE-352 CVE-2024-35207: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the vi
cvelistv5nvd
CVE-2024-35209MEDIUMCVSS 6.9fixed in 1.2fixed in V1.22024-06-11
CVE-2024-35209 [MEDIUM] CWE-749 CVE-2024-35209: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is allowing HTTP methods like PUT and Delete. This could allow an attacker to modify unauthorized files.
cvelistv5nvd
CVE-2024-35210MEDIUMCVSS 5.1fixed in 1.2fixed in V1.22024-06-11
CVE-2024-35210 [MEDIUM] CWE-319 CVE-2024-35210: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information.
cvelistv5nvd
CVE-2024-35211MEDIUMCVSS 6.8fixed in 1.2fixed in V1.22024-06-11
CVE-2024-35211 [MEDIUM] CWE-614 CVE-2024-35211: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server, after a successful login, sets the session cookie on the browser, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”).
cvelistv5nvd
CVE-2024-35208MEDIUMCVSS 4.8fixed in 1.2fixed in V1.22024-06-11
CVE-2024-35208 [MEDIUM] CWE-522 CVE-2024-35208: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password in cleartext. This could allow attacker in a privileged position to obtain access passwords.
cvelistv5nvd
CVE-2024-35212MEDIUMCVSS 6.9fixed in 1.2fixed in V1.22024-06-11
CVE-2024-35212 [MEDIUM] CWE-20 CVE-2024-35212: A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application lacks input validation due to which an attacker can gain access to the Database entries.
cvelistv5nvd