Use of a broken or risky cryptographic algorithm in SIRIUS 3RK3 Modular Safety System (MSS) and SIRIUS Safety Relays 3SK2 - CVE-2025-24007
Published: May 28, 2025
Vulnerability identifier: #VU109892
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-24007
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to weak password obfuscation. A remote attacker can retrieve and de-obfuscate the safety password used for protection against inadvertent operating errors.
Affected software
SIRIUS 3RK3 Modular Safety System (MSS)
SIRIUS Safety Relays 3SK2
SIRIUS Safety Relays 3SK2
How to mitigate CVE-2025-24007
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.