PT-2024-4461 · Siemens · Simatic Cn 4100

Martin Floeck

+1

·

Published

2024-05-14

·

Updated

2024-05-14

·

CVE-2024-32742

CVSS v3.1

7.6

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SIMATIC CN 4100 versions prior to V3.0
Description The issue is related to the absence of an immutable root of trust in the device's firmware, which can be exploited through an unrestricted USB port. This could allow an attacker with local access to the device to gain complete read/write access to the filesystem by potentially booting another operating system.
Recommendations For SIMATIC CN 4100 versions prior to V3.0, update to version V3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the USB port to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04963
CVE-2024-32742

Affected Products

Simatic Cn 4100