CVE Database
/

CVE-2024-43781

Back to search

CVE-2024-43781

Published: Sep 10, 2024

Modified: Sep 10, 2024

PUBLISHED

CVSS v3.1

5.5

MEDIUM

Description

A vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions < V4.95 SP3 in connection with using Create MyConfig (CMC) <= V4.8 SP1 HF6), SINUMERIK ONE (All versions < V6.23 in connection with using Create MyConfig (CMC) <= V6.6), SINUMERIK ONE (All versions < V6.15 SP4 in connection with using Create MyConfig (CMC) <= V6.6). Affected systems, that have been provisioned with Create MyConfig (CMC), contain a Insertion of Sensitive Information into Log File vulnerability. This could allow a local authenticated user with low privileges to read sensitive information and thus circumvent access restrictions.

VendorProductVersions

Siemens

SINUMERIK 828D V4

affected
0 - < V4.95 SP3

Siemens

SINUMERIK 840D sl V4

affected
0 - < V4.95 SP3

Siemens

SINUMERIK ONE

affected
0 - < V6.23

Siemens

SINUMERIK ONE

affected
0 - < V6.15 SP4

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now