Weak Password Obfuscation in SIRIUS 3RK3 Modular Safety System and Safety Relays 3SK2
CVE-2025-24007
8.7HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-24007?
A significant flaw has been discovered in the SIRIUS 3RK3 Modular Safety System and SIRIUS Safety Relays 3SK2, where inadequate password obfuscation can expose sensitive operational credentials. This vulnerability allows attackers with network access to potentially uncover and de-obfuscate safety passwords, raising concerns about the systems' protection against accidental operational errors. Proper measures should be implemented to enhance password security to mitigate risks associated with unauthorized access.
Affected Version(s)
SIRIUS 3RK3 Modular Safety System (MSS) 0
SIRIUS Safety Relays 3SK2 0