A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption. This could allow an unauthenticated remote attacker in a man-in-the-middle position to read sensitive data, such as administrator credentials, or modify data in transit.
2021-11-09T12:15:10.123
2024-11-21T06:23:57.903
Modified
CVSSv3.1: 7.4 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | siemens | climatix_pol909_firmware | < 11.34 | Yes |
Operating System | siemens | climatix_pol909_firmware | < 11.42 | Yes |
Hardware | siemens | climatix_pol909 | - | No |