CVE-2024-45386
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Feb 11, 2025
CWE ID 613
Summary
CVE-2024-45386 is a newly identified vulnerability affecting various versions of SIMATIC PCS neo, SIMOCODE ES, SIRIUS Safety ES, SIRIUS Soft Starter ES, and TIA Administrator. These products fail to properly invalidate user sessions upon logout, enabling unauthenticated attackers to reuse valid session tokens. This issue can potentially expose sensitive information or allow unauthorized access to affected systems. Users are strongly encouraged to update their software to the latest versions as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share