CVE-2024-37995

Sept. 18, 2024, 3:37 p.m.

9.1
Critical

Description

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions < V4.2), SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0) (All versions < V4.2), SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0) (All versions < V4.2), SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0) (All versions < V4.2), SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0) (All versions < V4.2), SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0) (All versions < V4.2), SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0) (All versions < V4.2), SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0) (All versions < V4.2), SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0) (All versions < V4.2), SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0) (All versions < V4.2), SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0) (All versions < V4.2), SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0) (All versions < V4.2), SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0) (All versions < V4.2), SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0) (All versions < V4.2), SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0) (All versions < V4.2), SIMATIC RF1140R (6GT2831-6CB00) (All versions < V1.1), SIMATIC RF1170R (6GT2831-6BB00) (All versions < V1.1), SIMATIC RF166C (6GT2002-0EE20) (All versions < V2.2), SIMATIC RF185C (6GT2002-0JE10) (All versions < V2.2), SIMATIC RF186C (6GT2002-0JE20) (All versions < V2.2), SIMATIC RF186CI (6GT2002-0JE50) (All versions < V2.2), SIMATIC RF188C (6GT2002-0JE40) (All versions < V2.2), SIMATIC RF188CI (6GT2002-0JE60) (All versions < V2.2), SIMATIC RF360R (6GT2801-5BA30) (All versions < V2.2). The affected application improperly handles error while a faulty certificate upload leading to crashing of application. This vulnerability could allow an attacker to disclose sensitive information.

Product(s) Impacted

Vendor Product Versions
Siemens
  • Simatic Rf360r Firmware
  • Simatic Rf360r
  • Simatic Rf1170r Firmware
  • Simatic Rf1170r
  • Simatic Rf1140r Firmware
  • Simatic Rf1140r
  • Simatic Reader Rf685r Fcc Firmware
  • Simatic Reader Rf685r Fcc
  • Simatic Reader Rf685r Etsi Firmware
  • Simatic Reader Rf685r Etsi
  • Simatic Reader Rf685r Cmiit Firmware
  • Simatic Reader Rf685r Cmiit
  • Simatic Reader Rf685r Arib Firmware
  • Simatic Reader Rf685r Arib
  • Simatic Reader Rf680r Fcc Firmware
  • Simatic Reader Rf680r Fcc
  • Simatic Reader Rf680r Etsi Firmware
  • Simatic Reader Rf680r Etsi
  • Simatic Reader Rf680r Cmiit Firmware
  • Simatic Reader Rf680r Cmiit
  • Simatic Reader Rf680r Arib Firmware
  • Simatic Reader Rf680r Arib
  • Simatic Reader Rf650r Fcc Firmware
  • Simatic Reader Rf650r Fcc
  • Simatic Reader Rf650r Etsi Firmware
  • Simatic Reader Rf650r Etsi
  • Simatic Reader Rf650r Cmiit Firmware
  • Simatic Reader Rf650r Cmiit
  • Simatic Reader Rf650r Arib Firmware
  • Simatic Reader Rf650r Arib
  • Simatic Reader Rf615r Fcc Firmware
  • Simatic Reader Rf615r Fcc
  • Simatic Reader Rf615r Etsi Firmware
  • Simatic Reader Rf615r Etsi
  • Simatic Reader Rf615r Cmiit Firmware
  • Simatic Reader Rf615r Cmiit
  • Simatic Reader Rf610r Fcc Firmware
  • Simatic Reader Rf610r Fcc
  • Simatic Reader Rf610r Etsi Firmware
  • Simatic Reader Rf610r Etsi
  • Simatic Reader Rf610r Cmiit Firmware
  • Simatic Reader Rf610r Cmiit
  • Simatic Rf188ci Firmware
  • Simatic Rf188ci
  • Simatic Rf188c Firmware
  • Simatic Rf188c
  • Simatic Rf186ci Firmware
  • Simatic Rf186ci
  • Simatic Rf186c Firmware
  • Simatic Rf186c
  • Simatic Rf185c Firmware
  • Simatic Rf185c
  • Simatic Rf166c Firmware
  • Simatic Rf166c
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-703
Improper Check or Handling of Exceptional Conditions
The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
o siemens simatic_rf360r_firmware / / / / / / / /
h siemens simatic_rf360r - / / / / / / /
o siemens simatic_rf1170r_firmware / / / / / / / /
h siemens simatic_rf1170r - / / / / / / /
o siemens simatic_rf1140r_firmware / / / / / / / /
h siemens simatic_rf1140r - / / / / / / /
o siemens simatic_reader_rf685r_fcc_firmware / / / / / / / /
h siemens simatic_reader_rf685r_fcc - / / / / / / /
o siemens simatic_reader_rf685r_etsi_firmware / / / / / / / /
h siemens simatic_reader_rf685r_etsi - / / / / / / /
o siemens simatic_reader_rf685r_cmiit_firmware / / / / / / / /
h siemens simatic_reader_rf685r_cmiit - / / / / / / /
o siemens simatic_reader_rf685r_arib_firmware / / / / / / / /
h siemens simatic_reader_rf685r_arib - / / / / / / /
o siemens simatic_reader_rf680r_fcc_firmware / / / / / / / /
h siemens simatic_reader_rf680r_fcc - / / / / / / /
o siemens simatic_reader_rf680r_etsi_firmware / / / / / / / /
h siemens simatic_reader_rf680r_etsi - / / / / / / /
o siemens simatic_reader_rf680r_cmiit_firmware / / / / / / / /
h siemens simatic_reader_rf680r_cmiit - / / / / / / /
o siemens simatic_reader_rf680r_arib_firmware / / / / / / / /
h siemens simatic_reader_rf680r_arib - / / / / / / /
o siemens simatic_reader_rf650r_fcc_firmware / / / / / / / /
h siemens simatic_reader_rf650r_fcc - / / / / / / /
o siemens simatic_reader_rf650r_etsi_firmware / / / / / / / /
h siemens simatic_reader_rf650r_etsi - / / / / / / /
o siemens simatic_reader_rf650r_cmiit_firmware / / / / / / / /
h siemens simatic_reader_rf650r_cmiit - / / / / / / /
o siemens simatic_reader_rf650r_arib_firmware / / / / / / / /
h siemens simatic_reader_rf650r_arib - / / / / / / /
o siemens simatic_reader_rf615r_fcc_firmware / / / / / / / /
h siemens simatic_reader_rf615r_fcc - / / / / / / /
o siemens simatic_reader_rf615r_etsi_firmware / / / / / / / /
h siemens simatic_reader_rf615r_etsi - / / / / / / /
o siemens simatic_reader_rf615r_cmiit_firmware / / / / / / / /
h siemens simatic_reader_rf615r_cmiit - / / / / / / /
o siemens simatic_reader_rf610r_fcc_firmware / / / / / / / /
h siemens simatic_reader_rf610r_fcc - / / / / / / /
o siemens simatic_reader_rf610r_etsi_firmware / / / / / / / /
h siemens simatic_reader_rf610r_etsi - / / / / / / /
o siemens simatic_reader_rf610r_cmiit_firmware / / / / / / / /
h siemens simatic_reader_rf610r_cmiit - / / / / / / /
o siemens simatic_rf188ci_firmware / / / / / / / /
h siemens simatic_rf188ci - / / / / / / /
o siemens simatic_rf188c_firmware / / / / / / / /
h siemens simatic_rf188c - / / / / / / /
o siemens simatic_rf186ci_firmware / / / / / / / /
h siemens simatic_rf186ci - / / / / / / /
o siemens simatic_rf186c_firmware / / / / / / / /
h siemens simatic_rf186c - / / / / / / /
o siemens simatic_rf185c_firmware / / / / / / / /
h siemens simatic_rf185c - / / / / / / /
o siemens simatic_rf166c_firmware / / / / / / / /
h siemens simatic_rf166c - / / / / / / /

CVSS Score

9.1 / 10

CVSS Data - 3.1

  • Attack Vector: NETWORK
  • Attack Complexity: LOW
  • Privileges Required: NONE
  • Scope: UNCHANGED
  • Confidentiality Impact: HIGH
  • Integrity Impact: NONE
  • Availability Impact: HIGH
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

    View Vector String

Timeline

Published: Sept. 10, 2024, 10:15 a.m.
Last Modified: Sept. 18, 2024, 3:37 p.m.

Status : Analyzed

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

productcert@siemens.com

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.