Hidden Configuration Item Could Lead to Deployment Insights
CVE-2024-37994
7.1HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 10 September 2024
What is CVE-2024-37994?
A vulnerability has been detected in several SIMATIC Reader products, allowing potential attackers to exploit a hidden configuration item that enables debug functionality. This anomaly permits unauthorized access to the internal configuration settings of affected deployments. Specifically, it concerns all versions of the SIMATIC Reader RF610R, RF615R, RF650R, RF680R, RF685R, and others below the specified version thresholds. Organizations utilizing these products should take immediate action to address this security issue and protect their systems from potential exploitation.
Affected Version(s)
SIMATIC Reader RF610R CMIIT 0
SIMATIC Reader RF610R ETSI 0
SIMATIC Reader RF610R FCC 0