Inadequate Encryption Strength in Siemens products - CVE-2024-54089
Published: February 24, 2025
Vulnerability identifier: #VU104160
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-54089
CWE-ID: CWE-326
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a weak encryption mechanism based on a hard-coded key. A remote attacker can guess or decrypt the password from the cyphertext.
Affected software
APOGEE PXC Series (BACnet)
APOGEE PXC Series (P2 Ethernet)
TALON TC Series
APOGEE PXC Series (P2 Ethernet)
TALON TC Series
How to mitigate CVE-2024-54089
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.