CVE-2024-39675

A vulnerability has been identified in RUGGEDCOM RMC30 (All versions < V4.3.10), RUGGEDCOM RMC30NC (All versions < V4.3.10), RUGGEDCOM RP110 (All versions < V4.3.10), RUGGEDCOM RP110NC (All versions < V4.3.10), RUGGEDCOM RS400 (All versions < V4.3.10), RUGGEDCOM RS400NC (All versions < V4.3.10), RUGGEDCOM RS401 (All versions < V4.3.10), RUGGEDCOM RS401NC (All versions < V4.3.10), RUGGEDCOM RS416 (All versions < V4.3.10), RUGGEDCOM RS416NC (All versions < V4.3.10), RUGGEDCOM RS416NCv2 V4.X (All versions < V4.3.10), RUGGEDCOM RS416NCv2 V5.X (All versions < V5.9.0), RUGGEDCOM RS416P (All versions < V4.3.10), RUGGEDCOM RS416PNC (All versions < V4.3.10), RUGGEDCOM RS416PNCv2 V4.X (All versions < V4.3.10), RUGGEDCOM RS416PNCv2 V5.X (All versions < V5.9.0), RUGGEDCOM RS416Pv2 V4.X (All versions < V4.3.10), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.9.0), RUGGEDCOM RS416v2 V4.X (All versions < V4.3.10), RUGGEDCOM RS416v2 V5.X (All versions < V5.9.0), RUGGEDCOM RS910 (All versions < V4.3.10), RUGGEDCOM RS910L (All versions), RUGGEDCOM RS910LNC (All versions), RUGGEDCOM RS910NC (All versions < V4.3.10), RUGGEDCOM RS910W (All versions < V4.3.10), RUGGEDCOM RS920L (All versions), RUGGEDCOM RS920LNC (All versions), RUGGEDCOM RS920W (All versions). In some configurations the affected products wrongly enable the Modbus service in non-managed VLANS. Only serial devices are affected by this vulnerability.
Configurations

No configuration.

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-170375.html - () https://cert-portal.siemens.com/productcert/html/ssa-170375.html -
Summary
  • (es) Se ha identificado una vulnerabilidad en RUGGEDCOM RMC30 (Todas las versiones &lt; V4.3.10), RUGGEDCOM RMC30NC (Todas las versiones &lt; V4.3.10), RUGGEDCOM RP110 (Todas las versiones &lt; V4.3.10), RUGGEDCOM RP110NC (Todas las versiones &lt; V4.3.10), RUGGEDCOM RS400 (todas las versiones &lt; V4.3.10), RUGGEDCOM RS400NC (todas las versiones &lt; V4.3.10), RUGGEDCOM RS401 (todas las versiones &lt; V4.3.10), RUGGEDCOM RS401NC (todas las versiones &lt; V4.3.10), RUGGEDCOM RS416 (todas las versiones &lt; V4.3.10), RUGGEDCOM RS416NC (todas las versiones &lt; V4.3.10), RUGGEDCOM RS416NCv2 V4.X (todas las versiones &lt; V4.3.10), RUGGEDCOM RS416NCv2 V5.X (todas las versiones &lt; V5.9.0), RUGGEDCOM RS416P (todas las versiones &lt; V4.3.10), RUGGEDCOM RS416PNC (todas las versiones &lt; V4.3.10), RUGGEDCOM RS416PNCv2 V4.X (todas las versiones &lt; V4.3.10), RUGGEDCOM RS416PNCv2 V5.X (todas las versiones &lt; V5.9.0), RUGGEDCOM RS416Pv2 V4.X ( Todas las versiones &lt; V4.3.10), RUGGEDCOM RS416Pv2 V5.X (Todas las versiones &lt; V5.9.0), RUGGEDCOM RS416v2 V4.X (Todas las versiones &lt; V4.3.10), RUGGEDCOM RS416v2 V5.X (Todas las versiones &lt; V5.9.0), RUGGEDCOM RS910 (todas las versiones &lt; V4.3.10), RUGGEDCOM RS910L (todas las versiones), RUGGEDCOM RS910LNC (todas las versiones), RUGGEDCOM RS910NC (todas las versiones &lt; V4.3.10), RUGGEDCOM RS910W (todas las versiones &lt; V4.3.10), RUGGEDCOM RS920L ( Todas las versiones), RUGGEDCOM RS920LNC (Todas las versiones), RUGGEDCOM RS920W (Todas las versiones). En algunas configuraciones los productos afectados habilitan erróneamente el servicio Modbus en VLAN no gestionadas. Sólo los dispositivos serie se ven afectados por esta vulnerabilidad.

09 Jul 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 12:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-39675

Mitre link : CVE-2024-39675

CVE.ORG link : CVE-2024-39675


JSON object : View

Products Affected

No product.

CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere