PT-2025-20850 · Siemens · Sirius Safety Relays 3Sk2+1

Published

2025-05-13

·

Updated

2025-05-13

·

CVE-2025-24009

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SIRIUS 3RK3 Modular Safety System (MSS) (All versions) SIRIUS Safety Relays 3SK2 (All versions)
Description: A vulnerability has been identified where the affected devices do not require authentication to access critical resources. An attacker with network access could retrieve sensitive information from certain data records, including obfuscated safety passwords.
Recommendations: For SIRIUS 3RK3 Modular Safety System (MSS) (All versions), restrict access to critical resources to minimize the risk of exploitation. For SIRIUS Safety Relays 3SK2 (All versions), restrict access to critical resources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2025-06752
CVE-2025-24009

Affected Products

Sirius 3Rk3 Modular Safety System
Sirius Safety Relays 3Sk2