Devices vulnerable to attack through web server component
CVE-2024-41977
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 13 August 2024
What is CVE-2024-41977?
A significant vulnerability has been discovered that affects multiple Siemens RUGGEDCOM and SCALANCE devices. The devices fail to enforce proper isolation between user sessions in their web server component. This oversight could potentially allow an authenticated remote attacker to escalate their privileges, thereby gaining unauthorized access to sensitive information or executing harmful commands on the affected devices. As a precaution, users are urged to update their systems to version 8.1 or later to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
RUGGEDCOM RM1224 LTE(4G) EU 0
RUGGEDCOM RM1224 LTE(4G) NAM 0
SCALANCE M804PB 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved