PT-2024-7406 · Siemens · Simatic Rf188C+11
Published
2024-09-10
·
Updated
2024-09-18
·
CVE-2024-37994
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
SIMATIC Reader RF610R CMIIT versions prior to V4.2
SIMATIC Reader RF610R ETSI versions prior to V4.2
SIMATIC Reader RF610R FCC versions prior to V4.2
SIMATIC Reader RF615R CMIIT versions prior to V4.2
SIMATIC Reader RF615R ETSI versions prior to V4.2
SIMATIC Reader RF615R FCC versions prior to V4.2
SIMATIC Reader RF650R ARIB versions prior to V4.2
SIMATIC Reader RF650R CMIIT versions prior to V4.2
SIMATIC Reader RF650R ETSI versions prior to V4.2
SIMATIC Reader RF650R FCC versions prior to V4.2
SIMATIC Reader RF680R ARIB versions prior to V4.2
SIMATIC Reader RF680R CMIIT versions prior to V4.2
SIMATIC Reader RF680R ETSI versions prior to V4.2
SIMATIC Reader RF680R FCC versions prior to V4.2
SIMATIC Reader RF685R ARIB versions prior to V4.2
SIMATIC Reader RF685R CMIIT versions prior to V4.2
SIMATIC Reader RF685R ETSI versions prior to V4.2
SIMATIC Reader RF685R FCC versions prior to V4.2
SIMATIC RF1140R versions prior to V1.1
SIMATIC RF1170R versions prior to V1.1
SIMATIC RF166C versions prior to V2.2
SIMATIC RF185C versions prior to V2.2
SIMATIC RF186C versions prior to V2.2
SIMATIC RF186CI versions prior to V2.2
SIMATIC RF188C versions prior to V2.2
SIMATIC RF188CI versions prior to V2.2
SIMATIC RF360R versions prior to V2.2
Description:
The affected application contains a hidden configuration item to enable debug functionality, which could allow an attacker to gain insight into the internal configuration of the deployment. This issue is related to the presence of undocumented configuration commands in the SIMATIC Reader software. Exploitation of this vulnerability may enable an attacker to activate the debug functionality.
Recommendations:
For SIMATIC Reader RF610R CMIIT versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF610R ETSI versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF610R FCC versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF615R CMIIT versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF615R ETSI versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF615R FCC versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF650R ARIB versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF650R CMIIT versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF650R ETSI versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF650R FCC versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF680R ARIB versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF680R CMIIT versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF680R ETSI versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF680R FCC versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF685R ARIB versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF685R CMIIT versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF685R ETSI versions prior to V4.2, update to version V4.2 or later.
For SIMATIC Reader RF685R FCC versions prior to V4.2, update to version V4.2 or later.
For SIMATIC RF1140R versions prior to V1.1, update to version V1.1 or later.
For SIMATIC RF1170R versions prior to V1.1, update to version V1.1 or later.
For SIMATIC RF166C versions prior to V2.2, update to version V2.2 or later.
For SIMATIC RF185C versions prior to V2.2, update to version V2.2 or later.
For SIMATIC RF186C versions prior to V2.2, update to version V2.2 or later.
For SIMATIC RF186CI versions prior to V2.2, update to version V2.2 or later.
For SIMATIC RF188C versions prior to V2.2, update to version V2.2 or later.
For SIMATIC RF188CI versions prior to V2.2, update to version V2.2 or later.
For SIMATIC RF360R versions prior to V2.2, update to version V2.2 or later.
Fix
Hidden Functionality
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Rf1140R
Simatic Rf1170R
Simatic Rf166C
Simatic Rf185C
Simatic Rf186Ci
Simatic Rf188C
Simatic Rf360R
Simatic Reader Rf610R
Simatic Reader Rf615R
Simatic Reader Rf650R
Simatic Reader Rf680R
Simatic Reader Rf685R