CVE-2024-41907
MEDIUMDescription
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to clickjacking attack.
Is your site exposed to CVE-2024-41907?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| siemens | sinec_traffic_analyzer |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-41907? +
How severe is CVE-2024-41907? +
What products are affected by CVE-2024-41907? +
How do I check if I'm vulnerable to CVE-2024-41907? +
Related Vulnerabilities
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / …
The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacker could …
Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the …
DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. …
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and …