CVE Database
/

CVE-2024-35292

Back to search

CVE-2024-35292

Published: Jun 11, 2024

Modified: Aug 2, 2024

PUBLISHED

CVSS v3.1

8.2

HIGH

Description

A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA1) (All versions). Affected devices are using a predictable IP ID sequence number. This leaves the system susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as their base method of attack and eventually could allow an attacker to create a denial of service condition.

VendorProductVersions

Siemens

SIMATIC S7-200 SMART CPU CR40

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU CR60

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR20

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR20

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR30

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR30

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR40

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR40

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR60

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU SR60

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST20

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST20

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST30

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST30

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST40

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST40

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST60

affected
0 - < *

Siemens

SIMATIC S7-200 SMART CPU ST60

affected
0 - < *

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:T/RC:C

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now