CVE & CISA-KEV Catalog

CVE-2024-37994

MEDIUM
4.3
CVSS v3
NVD

Description

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions < V4.2), SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0) (All versions < V4.2), SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0) (All versions < V4.2), SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0) (All versions < V4.2), SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0) (All versions < V4.2), SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0) (All versions < V4.2), SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0) (All versions < V4.2), SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0) (All versions < V4.2), SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0) (All versions < V4.2), SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0) (All versions < V4.2), SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0) (All versions < V4.2), SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0) (All versions < V4.2), SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0) (All versions < V4.2), SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0) (All versions < V4.2), SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0) (All versions < V4.2), SIMATIC RF1140R (6GT2831-6CB00) (All versions < V1.1), SIMATIC RF1170R (6GT2831-6BB00) (All versions < V1.1), SIMATIC RF166C (6GT2002-0EE20) (All versions < V2.2), SIMATIC RF185C (6GT2002-0JE10) (All versions < V2.2), SIMATIC RF186C (6GT2002-0JE20) (All versions < V2.2), SIMATIC RF186CI (6GT2002-0JE50) (All versions < V2.2), SIMATIC RF188C (6GT2002-0JE40) (All versions < V2.2), SIMATIC RF188CI (6GT2002-0JE60) (All versions < V2.2), SIMATIC RF360R (6GT2801-5BA30) (All versions < V2.2). The affected application contains a hidden configuration item to enable debug functionality. This could allow an attacker to gain insight into the internal configuration of the deployment.

How to fix

Remediation Available
simatic reader rf610r cmiit firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf610r etsi firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf610r fcc firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf615r cmiit firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf615r etsi firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf615r fcc firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf650r arib firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf650r cmiit firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf650r etsi firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf650r fcc firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf680r arib firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf680r cmiit firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf680r etsi firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf680r fcc firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf685r arib firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf685r cmiit firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf685r etsi firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic reader rf685r fcc firmwareNVD
Affected:< 4.2Fixed in:4.2CVE-2024-37994derived from NVD
simatic rf1140r firmwareNVD
Affected:< 1.1Fixed in:1.1CVE-2024-37994derived from NVD
simatic rf1170r firmwareNVD
Affected:< 1.1Fixed in:1.1CVE-2024-37994derived from NVD
simatic rf166c firmwareNVD
Affected:< 2.2Fixed in:2.2CVE-2024-37994derived from NVD
simatic rf185c firmwareNVD
Affected:< 2.2Fixed in:2.2CVE-2024-37994derived from NVD
simatic rf186c firmwareNVD
Affected:< 2.2Fixed in:2.2CVE-2024-37994derived from NVD
simatic rf186ci firmwareNVD
Affected:< 2.2Fixed in:2.2CVE-2024-37994derived from NVD
simatic rf188c firmwareNVD
Affected:< 2.2Fixed in:2.2CVE-2024-37994derived from NVD
simatic rf188ci firmwareNVD
Affected:< 2.2Fixed in:2.2CVE-2024-37994derived from NVD
simatic rf360r firmwareNVD
Affected:< 2.2Fixed in:2.2CVE-2024-37994derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityNone
IntegrityLow
AvailabilityNone

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Exploit Intelligence

0.30%probability of exploitation in 30 days
22ndpercentile

Low risk: more likely to be exploited than 22% of all known CVEs.

References

Vendor Advisory1
Embed a live status badge for CVE-2024-37994
CVE-2024-37994 severity badge

Markdown

[![CVE-2024-37994](https://tridentstack.com/cve/badge/CVE-2024-37994.svg)](https://tridentstack.com/cve/CVE-2024-37994)

HTML

<a href="https://tridentstack.com/cve/CVE-2024-37994"><img src="https://tridentstack.com/cve/badge/CVE-2024-37994.svg" alt="CVE-2024-37994"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-09-18.