Missing Encryption of Sensitive Data in Climatix POL909 - CVE-2021-40366
Published: November 15, 2021
Climatix POL909
Siemens
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the web server of affected devices transmits data without TLS encryption. A remote attacker can perform a man-in-the-middle (MitM) attack and read sensitive data, such as administrator credentials, or modify data in transit.