CVE-2024-35292
Published: Jun 11, 2024
Modified: Aug 2, 2024
CVSS v3.1
8.2
Description
A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA1) (All versions). Affected devices are using a predictable IP ID sequence number. This leaves the system susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as their base method of attack and eventually could allow an attacker to create a denial of service condition.
| Vendor | Product | Versions |
|---|---|---|
Siemens | SIMATIC S7-200 SMART CPU CR40 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU CR60 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU SR20 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU SR20 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU SR30 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU SR30 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU SR40 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU SR40 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU SR60 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU SR60 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU ST20 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU ST20 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU ST30 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU ST30 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU ST40 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU ST40 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU ST60 | affected 0 - < * |
Siemens | SIMATIC S7-200 SMART CPU ST60 | affected 0 - < * |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:T/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now