First published: Tue Aug 13 2024(Updated: )
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1 ADSL-Router family (All versions < V8.1), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8.1), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2) (All versions < V8.1), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V8.1), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V8.1), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V8.1), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V8.1), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V8.1), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1) (All versions < V8.1), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1) (All versions < V8.1), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V8.1), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1) (All versions < V8.1), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1) (All versions < V8.1), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1) (All versions < V8.1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V8.1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V8.1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V8.1), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V8.1). Affected devices insert sensitive information about the generation of 2FA tokens into log files. This could allow an authenticated remote attacker to forge 2FA tokens of other users.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Siemens Ruggedcom RM1224 LTE(4G) EU Firmware | <8.1 | |
Siemens Ruggedcom RM1224 LTE(4G) EU | ||
All of | ||
Siemens Ruggedcom RM1224 LTE (4G) NAM Firmware | <8.1 | |
Siemens Ruggedcom RM1224 LTE (4G) NAM | ||
All of | ||
siemens scalance m804pb firmware | <8.1 | |
Siemens SCALANCE M804PB | ||
All of | ||
Siemens Scalance M826-2 SHDSL-Router Firmware | <8.1 | |
Siemens Scalance M826-2 SHDSL-Router Firmware | ||
All of | ||
siemens scalance m874-2 firmware | <8.1 | |
siemens scalance m874-2 | ||
All of | ||
siemens scalance m874-3 firmware | <8.1 | |
Siemens SCALANCE M874-3 | ||
All of | ||
siemens scalance m876-3 firmware | <8.1 | |
siemens scalance m876-3 | ||
All of | ||
siemens scalance m876-4 firmware | <8.1 | |
Siemens SCALANCE M876-4 (EU) Firmware | ||
All of | ||
Siemens SCALANCE M874-3 3G-Router (CN) Firmware | <8.1 | |
Siemens SCALANCE M874-3 3G-Router (CN) | ||
All of | ||
siemens SCALANCE M876-3 (rok) firmware | <8.1 | |
Siemens SCALANCE M876-3 (rok) | ||
All of | ||
Siemens SCALANCE M876-4 (EU) Firmware | <8.1 | |
Siemens SCALANCE M876-4 | ||
All of | ||
Siemens SCALANCE M876-4 (NAM) Firmware | <8.1 | |
Siemens SCALANCE M876-4 | ||
All of | ||
Siemens SCALANCE MUM853-1 (a1) firmware | <8.1 | |
Siemens SCALANCE MUM853-1 | ||
All of | ||
Siemens SCALANCE MUM853-1 (b1) firmware | <8.1 | |
siemens SCALANCE MUM853-1 (b1) | ||
All of | ||
Siemens SCALANCE MUM853-1 (eu) Firmware | <8.1 | |
Siemens SCALANCE MUM853-1 (EU) | ||
All of | ||
Siemens SCALANCE MUM856-1 (a1) firmware | <8.1 | |
Siemens SCALANCE MUM856-1 (a1) | ||
All of | ||
Siemens SCALANCE MUM856-1 (b1) Firmware | <8.1 | |
Siemens SCALANCE MUM856-1 (b1) | ||
All of | ||
Siemens SCALANCE MUM856-1 (cn) firmware | <8.1 | |
siemens SCALANCE MUM856-1 (cn) | ||
All of | ||
siemens SCALANCE MUM856-1 (eu) firmware | <8.1 | |
Siemens SCALANCE MUM856-1 (eu) | ||
All of | ||
Siemens SCALANCE MUM856-1 Firmware | <8.1 | |
Siemens SCALANCE MUM856-1 (ROW) | ||
All of | ||
Siemens SCALANCE S615 EEC LAN-Router | <8.1 | |
Siemens SCALANCE S615 EEC LAN-Router | ||
All of | ||
Siemens Scalance S615 EEC Firmware | <8.1 | |
Siemens SCALANCE S615 LAN-Router | ||
All of | ||
Siemens SCALANCE M812-1 Firmware | <8.1 | |
Siemens SCALANCE M812-1 (Annex A) | ||
All of | ||
Siemens SCALANCE M812-1 (Annex B) Firmware | <8.1 | |
Siemens SCALANCE M812-1 (annex b) | ||
All of | ||
Siemens SCALANCE M816-1 (Annex A) Firmware | <8.1 | |
siemens SCALANCE M816-1 (annex a) | ||
All of | ||
siemens SCALANCE M816-1 (annex b) firmware | <8.1 | |
Siemens SCALANCE M816-1 (annex b) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-41978 is currently assessed as critical due to its potential impact on vulnerable Siemens devices.
To fix CVE-2024-41978, upgrade all affected Siemens devices to firmware version 8.1 or higher.
CVE-2024-41978 affects multiple Siemens devices including RUGGEDCOM RM1224 LTE (4G), SCALANCE M804PB, and several models of SCALANCE routers.
If CVE-2024-41978 is not addressed, your devices may be vulnerable to unauthorized access and potential exploitation by attackers.
As of now, there is no public information indicating that CVE-2024-41978 is actively being exploited in the wild.