Devices vulnerable to attack through web server component
CVE-2024-41977

8HIGH

Key Information:

Summary

A significant vulnerability has been discovered that affects multiple Siemens RUGGEDCOM and SCALANCE devices. The devices fail to enforce proper isolation between user sessions in their web server component. This oversight could potentially allow an authenticated remote attacker to escalate their privileges, thereby gaining unauthorized access to sensitive information or executing harmful commands on the affected devices. As a precaution, users are urged to update their systems to version 8.1 or later to mitigate this risk.

Affected Version(s)

RUGGEDCOM RM1224 LTE(4G) EU 0

RUGGEDCOM RM1224 LTE(4G) NAM 0

SCALANCE M804PB 0

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.