Downgrade Vulnerability Affects CPCI85 Devices
CVE-2024-39601
6.5MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 22 July 2024
Summary
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Affected devices allow a remote authenticated user or an unauthenticated user with physical access to downgrade the firmware of the device. This could allow an attacker to downgrade the device to older versions with known vulnerabilities.
Affected Version(s)
CPCI85 Central Processing/Communication 0
SICORE Base system 0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published