SIMATIC Reader vulnerabilities due to error handling
CVE-2024-37992

7.5HIGH

Key Information:

Summary

A vulnerability has been identified in various models of Siemens' SIMATIC Reader series, including models RF610R, RF615R, RF650R, RF680R, and RF685R, among others, specifically in versions prior to V4.2. This vulnerability arises from improper error handling when setting SNMP, particularly when character limits are exceeded. Such errors can result in unexpected application restarts, potentially impacting the performance and reliability of connected systems.

Affected Version(s)

SIMATIC Reader RF610R CMIIT 0

SIMATIC Reader RF610R ETSI 0

SIMATIC Reader RF610R FCC 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.