CVE-2024-22044: High severity SENTRON 3KC ATC6 Expansion Module Ethernet vulnerability
A vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affected devices expose an unused, unstable http service at port 80/tcp on the Modbus-TCP Ethernet. This could allow an attacker on the same Modbus network to create a denial of service condition that forces the device to reboot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22044?
CVE-2024-22044 is classified as a vulnerability that could lead to a denial of service on affected devices.
How do I fix CVE-2024-22044?
To fix CVE-2024-22044, it is recommended to disable the unused HTTP service at port 80/tcp on the affected devices.
Which devices are affected by CVE-2024-22044?
CVE-2024-22044 affects all versions of the SENTRON 3KC ATC6 Expansion Module Ethernet.
What type of attack can be executed due to CVE-2024-22044?
An attacker on the same Modbus network could leverage CVE-2024-22044 to execute a denial of service attack.
Is there a workaround for CVE-2024-22044?
Yes, the recommended workaround for CVE-2024-22044 is to remove or secure access to the HTTP service at port 80/tcp.