CVE-2024-45032: Siemens Industrial Edge Management Pro
Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.
A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.3.1-1). Affected components do not properly validate the device tokens. This could allow an unauthenticated remote attacker to impersonate other devices onboarded to the system.
Affected products
- Siemens Industrial Edge Management Pro: before V1.9.5 (fixed in V1.9.5); before 1.9.5 (fixed in 1.9.5)
- Siemens Industrial Edge Management Virtual: before V2.3.1-1 (fixed in V2.3.1-1); before 2.3.1-1 (fixed in 2.3.1-1)
Published 2024-09-10. Last modified 2026-06-17.