Siemens Mendix SAML
A vulnerability in the Siemens Mendix SAML module allows unauthenticated remote attackers to hijack accounts in specific SSO configurations. This affects multiple versions of the Mendix SAML module, primarily used in critical infrastructure sectors like manufacturing and IT. Siemens has released vendor fixes and recommends updating to the latest version to mitigate the risk.
A vulnerability exists within the Siemens Mendix SAML module, impacting multiple versions including Mendix SAML (Mendix 10 compatible) versions prior to 4.2.3, Mendix SAML (Mendix 11 compatible) versions prior to 4.2.3, and Mendix SAML (Mendix 9.24 compatible) versions prior to 3.6.27. The vulnerability stems from a failure to properly validate the SAML response signature, enabling unauthenticated remote attackers to potentially hijack user accounts within specific Single Sign-On (SSO) configurations. This issue is particularly concerning due to the module's use in critical infrastructure sectors such as manufacturing and information technology. Siemens has proactively addressed this issue by releasing vendor fixes and strongly recommends that users update their systems to the latest version to eliminate the risk. The vulnerability was reported by Siemens ProductCERT and is now being disseminated through CISA advisories to increase awareness and facilitate remediation efforts. Siemens strongly recommends protecting network access to devices with appropriate mechanisms and configuring the environment according to Siemens' operational guidelines for Industrial Security.