CVE-2024-54092
A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (All versions), Industrial Edge Device Kit - arm64 V1.19 (All versions), Industrial Edge Device Kit - arm64 V1.20 (All versions < V1.20.2-1), Industrial Edge Device Kit - arm64 V1.21 (All versions < V1.21.1-1), Industrial Edge Device Kit - x86-64 V1.17 (All versions), Industrial Edge Device Kit - x86-64 V1.18 (All versions), Industrial Edge Device Kit - x86-64 V1.19 (All versions), Industrial Edge Device Kit - x86-64 V1.20 (All versions < V1.20.2-1), Industrial Edge Device Kit - x86-64 V1.21 (All versions < V1.21.1-1), Industrial Edge Own Device (IEOD) (All versions < V1.21.1-1-a), Industrial Edge Virtual Device (All versions < V1.21.1-1-a), SCALANCE LPE9413 (6GK5998-3GS01-2AC2) (All versions < V2.1), SIMATIC IPC BX-39A Industrial Edge Device (All versions < V3.0), SIMATIC IPC BX-59A Industrial Edge Device (All versions < V3.0), SIMATIC IPC127E Industrial Edge Device (All versions < V3.0), SIMATIC IPC227E Industrial Edge Device (All versions < V3.0), SIMATIC IPC427E Industrial Edge Device (All versions < V3.0), SIMATIC IPC847E Industrial Edge Device (All versions < V3.0). Affected devices do not properly enforce user authentication on specific API endpoints when identity federation is used. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that identity federation is currently or has previously been used and the attacker has learned the identity of a legitimate user.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.74%
- CWE
- CWE-1390
- Published
- 2025-04-08
- Last modified
- 2026-03-13
Affected products
- Siemens Industrial Edge Device Kit - arm64 V1.17
- Siemens Industrial Edge Device Kit - arm64 V1.18
- Siemens Industrial Edge Device Kit - arm64 V1.19
- Siemens Industrial Edge Device Kit - arm64 V1.20
- Siemens Industrial Edge Device Kit - arm64 V1.21
- Siemens Industrial Edge Device Kit - x86-64 V1.17
- Siemens Industrial Edge Device Kit - x86-64 V1.18
- Siemens Industrial Edge Device Kit - x86-64 V1.19
Weakness type
Related vulnerabilities
- CVE-2025-40552 — SolarWinds Web Help Desk Authentication Bypass Vulnerability
- CVE-2025-40554 — SolarWinds Web Help Desk Authentication Bypass Vulnerability
- CVE-2025-30412 — Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis
- CVE-2025-30411 — Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis
- CVE-2025-39596 — WordPress Quentn WP <= 1.2.8 - Privilege Escalation Vulnerability
- CVE-2025-1387 — Learning Digital Orca HCM - Improper Authentication
- CVE-2025-12871 — aEnrich|a+HRD - Authentication Abuse
- CVE-2025-12870 — aEnrich|eHRD - Authentication Abuse