PT-2024-8716 · Siemens · Simatic Cp 1543Sp-1

Published

2024-11-11

·

Updated

2025-09-22

·

CVE-2024-50310

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SIMATIC CP 1543-1 versions 4.0.44 through 4.0.49
Description The issue is related to improper authorization handling in the SIMATIC CP 1543-1 communication module's firmware. This could allow an unauthenticated remote attacker to bypass existing security restrictions and gain access to the filesystem.
Recommendations For versions 4.0.44 through 4.0.49, update to version 4.0.50 or later to secure the system. As a temporary workaround, consider restricting access to the filesystem until a patch is applied.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-10319
CVE-2024-50310

Affected Products

Simatic Cp 1543Sp-1