Exposure of Sensitive Information to an Unauthorized Actor (CWE-200)
A vulnerability has been identified in multiple SIMATIC Reader RF models and SIMATIC RF models. The service log files of the affected application can be accessed without proper authentication. This could allow an unauthenticated attacker to get access to sensitive information.
This vulnerability could lead to unauthorized access to sensitive information stored in service log files. An attacker could potentially use this information for further attacks or to gain insights into the system's configuration and operations. The confidentiality impact is rated as HIGH, while integrity and availability are not directly affected.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Siemens has released updates to address this vulnerability. Users should upgrade to version 4.2 or later for SIMATIC Reader RF models, version 2.2 or later for SIMATIC RF360R and RF166C/185C/186C/188C models, and version 1.1 or later for SIMATIC RF1140R and RF1170R models.
1. Update all affected SIMATIC Reader RF and SIMATIC RF models to the latest firmware versions as provided by Siemens. 2. If immediate updating is not possible, implement network segmentation and restrict access to the affected devices. 3. Monitor and audit access to service log files. 4. Implement strong authentication mechanisms for accessing system logs and sensitive information. 5. Follow the principle of least privilege for user accounts and system access. 6. Regularly review and update security configurations for all SIMATIC devices.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
NVD published the first details for CVE-2024-37991
A CVSS base score of 5.3 has been assigned.
Feedly found the first article mentioning CVE-2024-37991. See article
Feedly estimated the CVSS score as MEDIUM
EPSS Score was set to: 0.04% (Percentile: 9.6%)
A CVSS base score of 6.5 has been assigned.