SIMATIC Reader vulnerabilities due to error handling
CVE-2024-37992
7.5HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 10 September 2024
Summary
A vulnerability has been identified in various models of Siemens' SIMATIC Reader series, including models RF610R, RF615R, RF650R, RF680R, and RF685R, among others, specifically in versions prior to V4.2. This vulnerability arises from improper error handling when setting SNMP, particularly when character limits are exceeded. Such errors can result in unexpected application restarts, potentially impacting the performance and reliability of connected systems.
Affected Version(s)
SIMATIC Reader RF610R CMIIT 0
SIMATIC Reader RF610R ETSI 0
SIMATIC Reader RF610R FCC 0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved