CVE Database
/

CVE-2024-54092

Back to search

CVE-2024-54092

Published: Apr 8, 2025

Modified: Jul 8, 2025

PUBLISHED

CVSS v3.1

9.8

CRITICAL

Description

A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (All versions), Industrial Edge Device Kit - arm64 V1.19 (All versions), Industrial Edge Device Kit - arm64 V1.20 (All versions < V1.20.2-1), Industrial Edge Device Kit - arm64 V1.21 (All versions < V1.21.1-1), Industrial Edge Device Kit - x86-64 V1.17 (All versions), Industrial Edge Device Kit - x86-64 V1.18 (All versions), Industrial Edge Device Kit - x86-64 V1.19 (All versions), Industrial Edge Device Kit - x86-64 V1.20 (All versions < V1.20.2-1), Industrial Edge Device Kit - x86-64 V1.21 (All versions < V1.21.1-1), Industrial Edge Own Device (IEOD) (All versions < V1.21.1-1-a), Industrial Edge Virtual Device (All versions < V1.21.1-1-a), SCALANCE LPE9413 (6GK5998-3GS01-2AC2) (All versions < V2.1), SIMATIC IPC BX-39A Industrial Edge Device (All versions < V3.0), SIMATIC IPC BX-59A Industrial Edge Device (All versions < V3.0), SIMATIC IPC127E Industrial Edge Device (All versions < V3.0), SIMATIC IPC227E Industrial Edge Device (All versions < V3.0), SIMATIC IPC427E Industrial Edge Device (All versions < V3.0), SIMATIC IPC847E Industrial Edge Device (All versions < V3.0). Affected devices do not properly enforce user authentication on specific API endpoints when identity federation is used. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that identity federation is currently or has previously been used and the attacker has learned the identity of a legitimate user.

VendorProductVersions

Siemens

Industrial Edge Device Kit - arm64 V1.17

affected
0 - < *

Siemens

Industrial Edge Device Kit - arm64 V1.18

affected
0 - < *

Siemens

Industrial Edge Device Kit - arm64 V1.19

affected
0 - < *

Siemens

Industrial Edge Device Kit - arm64 V1.20

affected
0 - < V1.20.2-1

Siemens

Industrial Edge Device Kit - arm64 V1.21

affected
0 - < V1.21.1-1

Siemens

Industrial Edge Device Kit - x86-64 V1.17

affected
0 - < *

Siemens

Industrial Edge Device Kit - x86-64 V1.18

affected
0 - < *

Siemens

Industrial Edge Device Kit - x86-64 V1.19

affected
0 - < *

Siemens

Industrial Edge Device Kit - x86-64 V1.20

affected
0 - < V1.20.2-1

Siemens

Industrial Edge Device Kit - x86-64 V1.21

affected
0 - < V1.21.1-1

Siemens

Industrial Edge Own Device (IEOD)

affected
0 - < V1.21.1-1-a

Siemens

Industrial Edge Virtual Device

affected
0 - < V1.21.1-1-a

Siemens

SCALANCE LPE9413

affected
0 - < V2.1

Siemens

SIMATIC IPC BX-39A Industrial Edge Device

affected
0 - < V3.0

Siemens

SIMATIC IPC BX-59A Industrial Edge Device

affected
0 - < V3.0

Siemens

SIMATIC IPC127E Industrial Edge Device

affected
0 - < V3.0

Siemens

SIMATIC IPC227E Industrial Edge Device

affected
0 - < V3.0

Siemens

SIMATIC IPC427E Industrial Edge Device

affected
0 - < V3.0

Siemens

SIMATIC IPC847E Industrial Edge Device

affected
0 - < V3.0

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now