Lucene search

K
cvelistSiemensCVELIST:CVE-2024-37993
HistorySep 10, 2024 - 9:36 a.m.

CVE-2024-37993

2024-09-1009:36:39
CWE-284
siemens
www.cve.org
1
simatic reader
rf610r
rf615r
rf650r
rf680r
rf685r
rf1140r
rf1170r
rf166c
rf185c
rf186c
rf186ci
rf188c
rf188ci
rf360r
denial of service
unauthenticated attacker
vulnerability

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVSS4

6.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N

EPSS

0.001

Percentile

17.8%

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions < V4.2), SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0) (All versions < V4.2), SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0) (All versions < V4.2), SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0) (All versions < V4.2), SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0) (All versions < V4.2), SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0) (All versions < V4.2), SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0) (All versions < V4.2), SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0) (All versions < V4.2), SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0) (All versions < V4.2), SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0) (All versions < V4.2), SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0) (All versions < V4.2), SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0) (All versions < V4.2), SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0) (All versions < V4.2), SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0) (All versions < V4.2), SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0) (All versions < V4.2), SIMATIC RF1140R (6GT2831-6CB00) (All versions < V1.1), SIMATIC RF1170R (6GT2831-6BB00) (All versions < V1.1), SIMATIC RF166C (6GT2002-0EE20) (All versions < V2.2), SIMATIC RF185C (6GT2002-0JE10) (All versions < V2.2), SIMATIC RF186C (6GT2002-0JE20) (All versions < V2.2), SIMATIC RF186CI (6GT2002-0JE50) (All versions < V2.2), SIMATIC RF188C (6GT2002-0JE40) (All versions < V2.2), SIMATIC RF188CI (6GT2002-0JE60) (All versions < V2.2), SIMATIC RF360R (6GT2801-5BA30) (All versions < V2.2). The affected applications do not authenticated the creation of Ajax2App instances. This could allow an unauthenticated attacker to cause a denial of service condition.

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF610R CMIIT",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF610R ETSI",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF610R FCC",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF615R CMIIT",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF615R ETSI",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF615R FCC",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF650R ARIB",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF650R CMIIT",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF650R ETSI",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF650R FCC",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF680R ARIB",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF680R CMIIT",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF680R ETSI",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF680R FCC",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF685R ARIB",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF685R CMIIT",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF685R ETSI",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC Reader RF685R FCC",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V4.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC RF1140R",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V1.1",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC RF1170R",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V1.1",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC RF166C",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V2.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC RF185C",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V2.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC RF186C",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V2.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC RF186CI",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V2.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC RF188C",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V2.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC RF188CI",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V2.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "SIMATIC RF360R",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "V2.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVSS4

6.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N

EPSS

0.001

Percentile

17.8%

Related for CVELIST:CVE-2024-37993