PT-2024-5126 · Unknown · Cpci85 Central Processing/Communication+1

Constantin Schieber-Knöbl

+3

·

Published

2024-07-22

·

Updated

2024-07-24

·

CVE-2024-39601

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: CPCI85 Central Processing/Communication versions prior to V5.40 SICORE Base system versions prior to V1.4.0
Description: A vulnerability has been identified that allows a remote authenticated user or an unauthenticated user with physical access to downgrade the firmware of the device. This could allow an attacker to downgrade the device to older versions with known vulnerabilities. The issue is related to the lack of authentication for a critical function, which can be exploited by a remote attacker to lower the device's firmware version.
Recommendations: For CPCI85 Central Processing/Communication versions prior to V5.40, update to version V5.40 or later to resolve the issue. For SICORE Base system versions prior to V1.4.0, update to version V1.4.0 or later to resolve the issue. As a temporary workaround, consider restricting physical access to the devices and limiting remote access to authenticated users only until a patch is applied.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-05673
CVE-2024-39601

Affected Products

Cpci85 Central Processing/Communication
Sicore Base System