CVE-2024-21483: Medium severity SENTRON 7KM PAC3120 AC/DC vulnerability

Published Mar 12, 2024
·
Updated

A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3120 DC (7KM3120-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 AC/DC (7KM3220-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 DC (7KM3220-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)). The read out protection of the internal flash of affected devices was not properly set at the end of the manufacturing process. An attacker with physical access to the device could read out the data.

Affected Software

4 affected components
SENTRON 7KM PAC3120 AC/DC>=V3.2.3<V3.2.4
SENTRON 7KM PAC3120 DC>=V3.2.3<V3.2.4
SENTRON 7KM PAC3220 AC/DC>=V3.2.3<V3.2.4
SENTRON 7KM PAC3220 DC>=V3.2.3<V3.2.4

Event History

Mar 12, 2024
CVE Published
via MITRE·10:21 AM
Data Sourced
via MITRE·10:21 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-21483?

CVE-2024-21483 has a critical severity due to the potential impact on the confidentiality and integrity of the affected systems.

2

What products are affected by CVE-2024-21483?

CVE-2024-21483 affects the SENTRON 7KM PAC3120 AC/DC and DC models, as well as the 7KM PAC3220 series, specifically versions from V3.2.3 up to but not including V3.2.4.

3

How do I fix CVE-2024-21483?

To fix CVE-2024-21483, update the affected products to version V3.2.4 or later.

4

When was CVE-2024-21483 identified?

CVE-2024-21483 was identified for devices manufactured between specific dates in late 2023.

5

What types of vulnerabilities does CVE-2024-21483 represent?

CVE-2024-21483 represents vulnerabilities related to improper handling that could lead to security breaches in affected SENTRON devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203