SIMATIC Reader vulnerability could lead to sensitive information disclosure
CVE-2024-37995
9.1CRITICAL
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 10 September 2024
Summary
An identified vulnerability in Siemens' SIMATIC Reader devices, specifically in various RF610R, RF615R, RF650R, RF680R, RF685R, RF1140R, RF1170R, RF166C, RF185C, RF186C, RF186CI, RF188C, RF188CI, and RF360R models, allows improper handling of errors arising from faulty certificate uploads. This flaw can lead to crashes of the affected applications and potential exposure of sensitive information.
Affected Version(s)
SIMATIC Reader RF610R CMIIT 0
SIMATIC Reader RF610R ETSI 0
SIMATIC Reader RF610R FCC 0
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved