CVE Database
/

CVE-2024-39675

Back to search

CVE-2024-39675

Published: Jul 9, 2024

Modified: Aug 27, 2025

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

A vulnerability has been identified in RUGGEDCOM RMC30 (All versions < V4.3.10), RUGGEDCOM RMC30NC (All versions < V4.3.10), RUGGEDCOM RP110 (All versions < V4.3.10), RUGGEDCOM RP110NC (All versions < V4.3.10), RUGGEDCOM RS400 (All versions < V4.3.10), RUGGEDCOM RS400NC (All versions < V4.3.10), RUGGEDCOM RS401 (All versions < V4.3.10), RUGGEDCOM RS401NC (All versions < V4.3.10), RUGGEDCOM RS416 (All versions < V4.3.10), RUGGEDCOM RS416NC (All versions < V4.3.10), RUGGEDCOM RS416NCv2 V4.X (All versions < V4.3.10), RUGGEDCOM RS416NCv2 V5.X (All versions < V5.9.0), RUGGEDCOM RS416P (All versions < V4.3.10), RUGGEDCOM RS416PNC (All versions < V4.3.10), RUGGEDCOM RS416PNCv2 V4.X (All versions < V4.3.10), RUGGEDCOM RS416PNCv2 V5.X (All versions < V5.9.0), RUGGEDCOM RS416Pv2 V4.X (All versions < V4.3.10), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.9.0), RUGGEDCOM RS416v2 V4.X (All versions < V4.3.10), RUGGEDCOM RS416v2 V5.X (All versions < V5.9.0), RUGGEDCOM RS910 (All versions < V4.3.10), RUGGEDCOM RS910L (All versions), RUGGEDCOM RS910LNC (All versions), RUGGEDCOM RS910NC (All versions < V4.3.10), RUGGEDCOM RS910W (All versions < V4.3.10), RUGGEDCOM RS920L (All versions), RUGGEDCOM RS920LNC (All versions), RUGGEDCOM RS920W (All versions). In some configurations the affected products wrongly enable the Modbus service in non-managed VLANS. Only serial devices are affected by this vulnerability.

VendorProductVersions

Siemens

RUGGEDCOM RMC30

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RMC30NC

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RP110

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RP110NC

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS400

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS400NC

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS401

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS401NC

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS416

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS416NC

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS416NCv2 V4.X

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS416NCv2 V5.X

affected
0 - < V5.9.0

Siemens

RUGGEDCOM RS416P

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS416PNC

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS416PNCv2 V4.X

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS416PNCv2 V5.X

affected
0 - < V5.9.0

Siemens

RUGGEDCOM RS416Pv2 V4.X

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS416Pv2 V5.X

affected
0 - < V5.9.0

Siemens

RUGGEDCOM RS416v2 V4.X

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS416v2 V5.X

affected
0 - < V5.9.0

Siemens

RUGGEDCOM RS910

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS910L

affected
0 - < *

Siemens

RUGGEDCOM RS910LNC

affected
0 - < *

Siemens

RUGGEDCOM RS910NC

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS910W

affected
0 - < V4.3.10

Siemens

RUGGEDCOM RS920L

affected
0 - < *

Siemens

RUGGEDCOM RS920LNC

affected
0 - < *

Siemens

RUGGEDCOM RS920W

affected
0 - < *

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now