Devices vulnerable to attack through web server component
CVE-2024-41977
8HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 13 August 2024
What is CVE-2024-41977?
A significant vulnerability has been discovered that affects multiple Siemens RUGGEDCOM and SCALANCE devices. The devices fail to enforce proper isolation between user sessions in their web server component. This oversight could potentially allow an authenticated remote attacker to escalate their privileges, thereby gaining unauthorized access to sensitive information or executing harmful commands on the affected devices. As a precaution, users are urged to update their systems to version 8.1 or later to mitigate this risk.
Affected Version(s)
RUGGEDCOM RM1224 LTE(4G) EU 0
RUGGEDCOM RM1224 LTE(4G) NAM 0
SCALANCE M804PB 0