CVE-2024-22044

A vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affected devices expose an unused, unstable http service at port 80/tcp on the Modbus-TCP Ethernet. This could allow an attacker on the same Modbus network to create a denial of service condition that forces the device to reboot.
Configurations

No configuration.

History

21 Nov 2024, 08:55

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-918992.html - () https://cert-portal.siemens.com/productcert/html/ssa-918992.html -
Summary
  • (es) Se ha identificado una vulnerabilidad en SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (Todas las versiones). Los dispositivos afectados exponen un servicio http inestable y no utilizado en el puerto 80/tcp en Modbus-TCP Ethernet. Esto podría permitir que un atacante en la misma red Modbus cree una condición de denegación de servicio que obligue al dispositivo a reiniciarse.

12 Mar 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-12 11:15

Updated : 2024-11-21 08:55


NVD link : CVE-2024-22044

Mitre link : CVE-2024-22044

CVE.ORG link : CVE-2024-22044


JSON object : View

Products Affected

No product.

CWE
CWE-912

Hidden Functionality