CVE-2021-40366 Information
Jun 07, 2022
cve
Description
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42) Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption. This could allow an unauthenticated remote attacker in a man-in-the-middle position to read sensitive data such as administrator credentials or modify data in transit.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Reference
https://cert-portal.siemens.com/productcert/pdf/ssa-703715.pdf
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
7.4
Share on: