Siemens ' research team , ProductCERT , has uncovered a critical vulnerability in Industrial Edge Management systems .

The vulnerability is tracked as CVE-2024-45032 and could allow unauthorized, remote attackers to impersonate other devices within the system.
The vulnerability has a CVSS score of 10/10, making it very dangerous. It results from improper validation of device tokens, which could be exploited by attackers to bypass authorization mechanisms and gain access to vulnerable systems.
See also: Ivanti fixes vulnerability in Endpoint Management (EPM)
According to Siemens, the vulnerability affects multiple versions of its Industrial Edge Management products, including both Pro and Virtual editions.
Users are urged to update their systems to the latest versions to protect themselves.
As previously mentioned, the vulnerability allows attackers to "impersonate" devices, potentially leading to unauthorized access and control over industrial networks.
Siemens: Protection
Beyond the updates, Siemens advises users to follow some general security practices, such as protecting network access and properly configuring IT environments.
See also: Microsoft Patch Tuesday September 2024: Fix 79 vulnerabilities
The disclosure of this critical vulnerability in Siemens Industrial Edge systems highlights the importance of proactive risk managementfor the security of industrial systems. Organizations must remain vigilant and take the necessary precautions. By following best practices and implementing comprehensive security, organizations can strengthen their defenses against potential attacks and protect critical infrastructure.

It is also important for organizations to regularly review and update their security policies and procedures to ensure they are aligned with industry standards and regulations. This includes conducting regular risk assessments to identify any vulnerabilities that could be exploited by attackers.
See also: CISA: Adds three critical vulnerabilities to the KEV List
Additionally, the involvement of external security experts can provide valuable information and recommendations for improving system security.
In addition to these technical measures, companies should also prioritize creating a culture of cybersecurity awareness among employees. This includes educating employees on the importance of adhering to security protocols and best practices, as well as paying attention to potential social engineering attacks .
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: gbhackers.com
