USB Vulnerability Allows Attackers to Boot Another OS and Access File System

CVE-2024-32742
7.6HIGH

Key Information

Vendor
Siemens
Status
Simatic Cn 4100
Vendor
CVE Published:
14 May 2024

Summary

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains an unrestricted USB port. An attacker with local access to the device could potentially misuse the port for booting another operating system and gain complete read/write access to the filesystem.

Affected Version(s)

SIMATIC CN 4100 < 0

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.