Unsecured Bootloader Vulnerability in SINAMICS S200 by Siemens
CVE-2024-56336
9.5CRITICAL
Summary
A vulnerability exists in the SINAMICS S200 line of devices manufactured by Siemens, characterized by an unlocked bootloader. This oversight allows potential attackers to inject malicious code or install untrusted firmware on affected devices, undermining the foundational security features meant to safeguard against data manipulation and unauthorized access. Devices with serial numbers beginning with SZVS8, SZVS9, SZVS0, or SZVSN, in conjunction with an FS number of 02, are particularly at risk. It is crucial for users of these devices to implement mitigative measures to protect their systems.
Affected Version(s)
SINAMICS S200 0
References
CVSS V4
Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved