Affected applications do not authenticate the creation of Ajax2App instances
CVE-2024-37993
7.5HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 10 September 2024
What is CVE-2024-37993?
A vulnerability has been identified in several SIMATIC Reader products by Siemens, specifically in versions prior to V4.2. The flaw resides in the lack of authentication for the creation of Ajax2App instances. As a result, an unauthenticated attacker can exploit this vulnerability, potentially leading to a denial of service condition, thereby disrupting the normal operational capabilities of the affected devices.
Affected Version(s)
SIMATIC Reader RF610R CMIIT 0
SIMATIC Reader RF610R ETSI 0
SIMATIC Reader RF610R FCC 0