Denial of Service Vulnerability in MS/TP Point Pickup Module by Siemens
CVE-2025-24510

7.1HIGH

Key Information:

Vendor

Siemens

Vendor
CVE Published:
13 May 2025

What is CVE-2025-24510?

A vulnerability exists in the MS/TP Point Pickup Module that affects the handling of specific BACnet MSTP messages. An attacker within the same BACnet network can exploit this by sending specially crafted messages, which may cause the targeted device to enter a denial of service state. A power cycle is necessary to restore normal operations. This poses significant risks for operational continuity and system reliability.

Affected Version(s)

MS/TP Point Pickup Module 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-24510 : Denial of Service Vulnerability in MS/TP Point Pickup Module by Siemens