news.mlab.sh
Back to the feed
vulnerability

Siemens Opcenter X

Critical
Summary

Siemens Opcenter X versions prior to V2604 contain a critical authentication bypass vulnerability, allowing an unauthenticated attacker to gain full unauthorized access to the application. Siemens has released a new version and recommends immediate updates. This affects critical manufacturing operations worldwide.

Siemens Opcenter X versions before V2604 are vulnerable to an authentication bypass. The vulnerability stems from a failure to properly validate the algorithm specified in the JSON Web Token (JWT) header, enabling an unauthenticated remote attacker to forge arbitrary JWTs and bypass authentication mechanisms. This would allow an attacker to impersonate any user, including administrative accounts, and gain full unauthorized access to the application.

This vulnerability affects critical manufacturing operations globally, as Opcenter X is widely deployed in these sectors.

Siemens has released a new version of Opcenter X and strongly recommends that users update to the latest version immediately.

**Affected Products:**

  • Siemens Opcenter X
  • Siemens
  • Opcenter X < V2604

**Known Affected:** Worldwide

**Remediation:**

  • Update to V2604 or later version: https://support.sw.siemens.com/product/206159703/

**Relevant CWE:** CWE-347 Improper Verification of Cryptographic Signature

**Acknowledgments:**

  • Siemens ProductCERT reported this vulnerability to CISA.

**General Recommendations:**

  • Siemens strongly recommends protecting network access to devices with appropriate mechanisms.
  • Configure the environment according to Siemens' operational guidelines for Industrial Security (https://www.siemens.com/cert/operational-guidelines-industrial-security).
  • Implement secure remote access methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available.

**Why it Matters:** This vulnerability poses a significant risk to critical infrastructure, potentially allowing attackers to disrupt manufacturing operations and gain unauthorized access to sensitive data. Organizations should prioritize patching and implementing robust security controls.

Read the full article at CISA Advisories