Hidden Configuration Item Could Lead to Deployment Insights
CVE-2024-37994

7.1HIGH

Key Information:

Summary

A vulnerability has been detected in several SIMATIC Reader products, allowing potential attackers to exploit a hidden configuration item that enables debug functionality. This anomaly permits unauthorized access to the internal configuration settings of affected deployments. Specifically, it concerns all versions of the SIMATIC Reader RF610R, RF615R, RF650R, RF680R, RF685R, and others below the specified version thresholds. Organizations utilizing these products should take immediate action to address this security issue and protect their systems from potential exploitation.

Affected Version(s)

SIMATIC Reader RF610R CMIIT 0

SIMATIC Reader RF610R ETSI 0

SIMATIC Reader RF610R FCC 0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.