CVE-2024-54092
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-54092 is a newly identified vulnerability affecting various versions of Industrial Edge Device Kit on both arm64 and x86-64 architectures, Industrial Edge Own Device, Industrial Edge Virtual Device, SCALANCE LPE9413, and several SIMATIC IPC devices. The issue lies in the inadequate user authentication enforcement on specific API endpoints when identity federation is implemented. This flaw enables unauthenticated remote attackers to bypass authentication and assume the identity of a legitimate user, once they have obtained the identity of an existing user. The exploitation of this vulnerability necessitates the use or previous use of identity federation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.