ICSA-24-319-12
·
Published 2025-08-12
·
View on CISA ICS-CERT ↗
Siemens Mendix Runtime
CVSS 5.3
MEDIUM
CVEs (1)
Remediations
- For app user login: Do not use basic authentication, but setup an alternative authentication module (e.g. OIDC SSO, Mendix SSO, or SAML >= V4.0.0), or your own Identity Provider (IDP).
- For published REST and web services and oData APIs: Do not use basic authentication, but use Custom or Active Session authentication methods.
- Currently no fix is planned
- Update to V10.12.7 or later version
- Update to V10.16.0 or later version
- Update to V10.6.15 or later version
- Update to V9.24.29 or later version
Affected Vendors
Siemens
Affected Products (5)
Siemens
·
Mendix Runtime V8
vers:all/*
Siemens
·
Mendix Runtime V9
vers:intdot/<9.24.29
Siemens
·
Mendix Runtime V10
vers:intdot/<10.16.0
Siemens
·
Mendix Runtime V10.6
vers:intdot/<10.6.15
Siemens
·
Mendix Runtime V10.12
vers:intdot/<10.12.7
Affected Sectors
Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more