CVE-2024-47902: Critical severity siemens intermesh 7177 hybrid 2.0 subscriber vulnerability
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not authenticate GET requests that execute specific commands (such as ping) on operating system level.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47902?
The severity of CVE-2024-47902 is considered high due to the lack of authentication for GET requests on affected devices.
How do I fix CVE-2024-47902?
To fix CVE-2024-47902, upgrade the affected devices to Siemens InterMesh 7177 Hybrid 2.0 Subscriber version 8.2.12 or later, and InterMesh 7707 Fire Subscriber version 7.2.12 or later.
Which versions are affected by CVE-2024-47902?
CVE-2024-47902 affects all versions of InterMesh 7177 Hybrid 2.0 Subscriber prior to 8.2.12 and all versions of InterMesh 7707 Fire Subscriber prior to 7.2.12 if the IP interface is enabled.
Is the IP interface enabled by default in CVE-2024-47902?
No, the IP interface is not enabled by default in the InterMesh 7707 Fire Subscriber.
What types of devices are impacted by CVE-2024-47902?
CVE-2024-47902 impacts the Siemens InterMesh 7177 Hybrid 2.0 Subscriber and the Siemens InterMesh 7707 Fire Subscriber firmware.