CVE-2023-37482

Publication date

2025-02-11 10:26:27

Family

siemens

State

PUBLISHED

Description

The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames.