CVE-2024-41984
BaseFortify
Publication date: 2025-08-12
Last updated on: 2025-10-22
Assigner: Siemens AG
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| siemens | opcenter_quality | 13.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-209 | The product generates an error message that includes sensitive information about its environment, users, or associated data. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in SmartClient modules Opcenter QL Home (SC), SOA Audit, and SOA Cockpit (all versions >= V13.2 and < V2506). It occurs because the affected applications improperly handle errors when accessing an inaccessible resource, which can lead to exposing the system applications.
How can this vulnerability impact me? :
The vulnerability can lead to exposure of system applications due to improper error handling when accessing inaccessible resources. This exposure could potentially allow unauthorized users to gain information about the system, which might be leveraged for further attacks or exploitation.