CVE-2024-21483: Medium severity SENTRON 7KM PAC3120 AC/DC vulnerability
A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3120 DC (7KM3120-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 AC/DC (7KM3220-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 DC (7KM3220-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)). The read out protection of the internal flash of affected devices was not properly set at the end of the manufacturing process. An attacker with physical access to the device could read out the data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21483?
CVE-2024-21483 has a critical severity due to the potential impact on the confidentiality and integrity of the affected systems.
What products are affected by CVE-2024-21483?
CVE-2024-21483 affects the SENTRON 7KM PAC3120 AC/DC and DC models, as well as the 7KM PAC3220 series, specifically versions from V3.2.3 up to but not including V3.2.4.
How do I fix CVE-2024-21483?
To fix CVE-2024-21483, update the affected products to version V3.2.4 or later.
When was CVE-2024-21483 identified?
CVE-2024-21483 was identified for devices manufactured between specific dates in late 2023.
What types of vulnerabilities does CVE-2024-21483 represent?
CVE-2024-21483 represents vulnerabilities related to improper handling that could lead to security breaches in affected SENTRON devices.