A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application do not encrypt the communication in LDAP interface by default. This could allow an authenticated attacker to gain unauthorized access to sensitive information.
History

Tue, 12 Aug 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens smartclient Modules
Siemens soa Audit
Siemens soa Cockpit
Vendors & Products Siemens
Siemens smartclient Modules
Siemens soa Audit
Siemens soa Cockpit

Tue, 12 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Aug 2025 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application do not encrypt the communication in LDAP interface by default. This could allow an authenticated attacker to gain unauthorized access to sensitive information.
Weaknesses CWE-311
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2025-08-12T11:16:35.999Z

Updated: 2025-08-12T15:54:00.509Z

Reserved: 2024-07-25T12:46:30.322Z

Link: CVE-2024-41980

cve-icon Vulnrichment

Updated: 2025-08-12T15:53:46.169Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-12T12:15:32.213

Modified: 2025-08-12T14:25:33.177

Link: CVE-2024-41980

cve-icon Redhat

No data.