Downgrade Vulnerability Affects CPCI85 Devices
CVE-2024-39601
7.1HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 22 July 2024
What is CVE-2024-39601?
A significant vulnerability has been detected in Siemens' CPCI85 Central Processing/Communication and SICORE Base system, where both systems permit remote authenticated users or unauthenticated users with physical access to downgrade the firmware. This capability may enable attackers to revert the systems to earlier firmware versions that contain known security weaknesses, thereby increasing the risk of exploitation and unauthorized access.
Affected Version(s)
CPCI85 Central Processing/Communication 0
SICORE Base system 0