CVE-2021-40366
09.11.2021, 12:15
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption. This could allow an unauthenticated remote attacker in a man-in-the-middle position to read sensitive data, such as administrator credentials, or modify data in transit.Enginsight
Vendor | Product | Version |
---|---|---|
siemens | climatix_pol909_firmware | 𝑥 < 11.34 |
siemens | climatix_pol909_firmware | 𝑥 < 11.42 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-311 - Missing Encryption of Sensitive DataThe software does not encrypt sensitive or critical information before storage or transmission.
- CWE-319 - Cleartext Transmission of Sensitive InformationThe software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.