ID

VAR-202408-0002


CVE

CVE-2024-41978


TITLE

Vulnerability related to information leakage from log files in multiple Siemens products

Trust: 0.8

sources: JVNDB: JVNDB-2024-006488

DESCRIPTION

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1 ADSL-Router family (All versions < V8.1), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8.1), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2) (All versions < V8.1), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V8.1), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V8.1), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V8.1), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V8.1), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V8.1), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1) (All versions < V8.1), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1) (All versions < V8.1), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V8.1), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1) (All versions < V8.1), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1) (All versions < V8.1), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1) (All versions < V8.1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V8.1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V8.1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V8.1), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V8.1). Affected devices insert sensitive information about the generation of 2FA tokens into log files. This could allow an authenticated remote attacker to forge 2FA tokens of other users. ruggedcom rm1224 lte(4g) eu firmware, ruggedcom rm1224 lte(4g) nam firmware, scalance m804pb Multiple Siemens products, including firmware, contain vulnerabilities that may allow information to be leaked from log files.Information may be obtained. SCALANCE M-800, MUM-800, S615, RUGGEDCOM RM1224 are all industrial routers. The Siemens SCALANCE M-800 series has an information disclosure vulnerability

Trust: 2.16

sources: NVD: CVE-2024-41978 // JVNDB: JVNDB-2024-006488 // CNVD: CNVD-2024-35436

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-35436

AFFECTED PRODUCTS

vendor:siemensmodel:scalance mum856-1 \scope:ltversion:8.1

Trust: 5.0

vendor:シーメンスmodel:scalance mum856-1scope: - version: -

Trust: 4.0

vendor:siemensmodel:scalance mum853-1 \scope:ltversion:8.1

Trust: 3.0

vendor:シーメンスmodel:scalance m876-4scope: - version: -

Trust: 2.4

vendor:シーメンスmodel:scalance mum853-1scope: - version: -

Trust: 2.4

vendor:siemensmodel:scalance m816-1 \scope:ltversion:8.1

Trust: 2.0

vendor:siemensmodel:scalance m876-4 \scope:ltversion:8.1

Trust: 2.0

vendor:siemensmodel:scalance m812-1 \scope:ltversion:8.1

Trust: 2.0

vendor:シーメンスmodel:scalance m876-3scope: - version: -

Trust: 1.6

vendor:siemensmodel:scalance s615 eec lan-routerscope:ltversion:8.1

Trust: 1.0

vendor:siemensmodel:scalance m874-3scope:ltversion:8.1

Trust: 1.0

vendor:siemensmodel:scalance m876-3scope:ltversion:8.1

Trust: 1.0

vendor:siemensmodel:scalance s615 lan-routerscope:ltversion:8.1

Trust: 1.0

vendor:siemensmodel:scalance m874-2scope:ltversion:8.1

Trust: 1.0

vendor:siemensmodel:scalance m826-2 shdsl-routerscope:ltversion:8.1

Trust: 1.0

vendor:siemensmodel:scalance m874-3 3g-router \scope:ltversion:8.1

Trust: 1.0

vendor:siemensmodel:scalance m876-3 \scope:ltversion:8.1

Trust: 1.0

vendor:siemensmodel:scalance m804pbscope:ltversion:8.1

Trust: 1.0

vendor:siemensmodel:ruggedcom rm1224 lte\ euscope:ltversion:8.1

Trust: 1.0

vendor:siemensmodel:scalance m876-4scope:ltversion:8.1

Trust: 1.0

vendor:siemensmodel:ruggedcom rm1224 lte\ namscope:ltversion:8.1

Trust: 1.0

vendor:シーメンスmodel:scalance m804pbscope: - version: -

Trust: 0.8

vendor:シーメンスmodel:scalance m874-3scope: - version: -

Trust: 0.8

vendor:シーメンスmodel:scalance m874-3 3g-routerscope: - version: -

Trust: 0.8

vendor:シーメンスmodel:scalance m874-2scope: - version: -

Trust: 0.8

vendor:シーメンスmodel:ruggedcom rm1224 lte euscope: - version: -

Trust: 0.8

vendor:シーメンスmodel:scalance m826-2 shdsl-routerscope: - version: -

Trust: 0.8

vendor:シーメンスmodel:ruggedcom rm1224 lte namscope: - version: -

Trust: 0.8

vendor:siemensmodel:scalance m-800 familyscope:ltversion:8.1

Trust: 0.6

sources: CNVD: CNVD-2024-35436 // JVNDB: JVNDB-2024-006488 // NVD: CVE-2024-41978

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-41978
value: MEDIUM

Trust: 1.0

productcert@siemens.com: CVE-2024-41978
value: HIGH

Trust: 1.0

NVD: CVE-2024-41978
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2024-35436
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2024-35436
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2024-41978
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 2.0

NVD: CVE-2024-41978
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2024-35436 // JVNDB: JVNDB-2024-006488 // NVD: CVE-2024-41978 // NVD: CVE-2024-41978

PROBLEMTYPE DATA

problemtype:CWE-532

Trust: 1.0

problemtype:Information leakage from log files (CWE-532) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-006488 // NVD: CVE-2024-41978

PATCH

title:Patch for Siemens SCALANCE M-800 Series Information Disclosure Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/576901

Trust: 0.6

sources: CNVD: CNVD-2024-35436

EXTERNAL IDS

db:NVDid:CVE-2024-41978

Trust: 3.2

db:SIEMENSid:SSA-087301

Trust: 2.4

db:JVNid:JVNVU99084687

Trust: 0.8

db:ICS CERTid:ICSA-24-228-01

Trust: 0.8

db:JVNDBid:JVNDB-2024-006488

Trust: 0.8

db:CNVDid:CNVD-2024-35436

Trust: 0.6

sources: CNVD: CNVD-2024-35436 // JVNDB: JVNDB-2024-006488 // NVD: CVE-2024-41978

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-087301.html

Trust: 2.4

url:https://jvn.jp/vu/jvnvu99084687/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-41978

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-24-228-01

Trust: 0.8

sources: CNVD: CNVD-2024-35436 // JVNDB: JVNDB-2024-006488 // NVD: CVE-2024-41978

SOURCES

db:CNVDid:CNVD-2024-35436
db:JVNDBid:JVNDB-2024-006488
db:NVDid:CVE-2024-41978

LAST UPDATE DATE

2024-08-27T19:21:24.432000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-35436date:2024-08-14T00:00:00
db:JVNDBid:JVNDB-2024-006488date:2024-08-26T05:09:00
db:NVDid:CVE-2024-41978date:2024-08-23T18:34:36.283

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-35436date:2024-08-14T00:00:00
db:JVNDBid:JVNDB-2024-006488date:2024-08-26T00:00:00
db:NVDid:CVE-2024-41978date:2024-08-13T08:15:15.903