Affected applications do not authenticate the creation of Ajax2App instances
CVE-2024-37993

7.5HIGH

Key Information:

Summary

A vulnerability has been identified in several SIMATIC Reader products by Siemens, specifically in versions prior to V4.2. The flaw resides in the lack of authentication for the creation of Ajax2App instances. As a result, an unauthenticated attacker can exploit this vulnerability, potentially leading to a denial of service condition, thereby disrupting the normal operational capabilities of the affected devices.

Affected Version(s)

SIMATIC Reader RF610R CMIIT 0

SIMATIC Reader RF610R ETSI 0

SIMATIC Reader RF610R FCC 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.