Improper access control in Siemens products - CVE-2024-21483
Published: March 13, 2024
Vulnerability identifier: #VU87485
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21483
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. An attacker with physical access can bypass implemented security restrictions and gain unauthorized access to sensitive information.
Affected software
SENTRON 7KM PAC3120 AC/DC
SENTRON 7KM PAC3120 DC
SENTRON 7KM PAC3220 AC/DC
SENTRON 7KM PAC3220 DC
SENTRON 7KM PAC3120 DC
SENTRON 7KM PAC3220 AC/DC
SENTRON 7KM PAC3220 DC
How to mitigate CVE-2024-21483
Install updates from vendor's website.
SENTRON 7KM PAC3120 AC/DC - update to 3.3.0
SENTRON 7KM PAC3120 DC - update to 3.3.0
SENTRON 7KM PAC3220 AC/DC - update to 3.3.0
SENTRON 7KM PAC3220 DC - update to 3.3.0
SENTRON 7KM PAC3120 DC - update to 3.3.0
SENTRON 7KM PAC3220 AC/DC - update to 3.3.0
SENTRON 7KM PAC3220 DC - update to 3.3.0