CVE-2024-41978
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1 ADSL-Router family (All versions < V8.1), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8.1), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2) (All versions < V8.1), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V8.1), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V8.1), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V8.1), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V8.1), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V8.1), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1) (All versions < V8.1), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1) (All versions < V8.1), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V8.1), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1) (All versions < V8.1), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1) (All versions < V8.1), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1) (All versions < V8.1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V8.1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V8.1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V8.1), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V8.1). Affected devices insert sensitive information about the generation of 2FA tokens into log files. This could allow an authenticated remote attacker to forge 2FA tokens of other users.
EPSS 0.34% · 56.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SCALANCE M876-3 | 0 |
| Siemens | SCALANCE M826-2 SHDSL-Router | 0 |
| Siemens | SCALANCE M804PB | 0 |
| siemens | scalance_mum856-1_\(cn\)_firmware | 0 |
| siemens | ruggedcom_rm1224_lte\(4g\)_nam_firmware | 0 |
| siemens | scalance_mum856-1_\(b1\)_firmware | 0 |
| siemens | scalance_m876-4_\(eu\)_firmware | 0 |
| siemens | scalance_m804pb_firmware | 0 |
| Siemens | SCALANCE S615 LAN-Router | 0 |
| siemens | scalance_s615_lan-router_firmware | 0 |
| siemens | scalance_m812-1_\(annex_b\)_firmware | 0 |
| Siemens | SCALANCE M816-1 ADSL-Router family | 0 |
| Siemens | SCALANCE M876-4 | 0 |
| Siemens | SCALANCE M874-2 | 0 |
| Siemens | SCALANCE M876-3 (ROK) | 0 |
| siemens | scalance_mum856-1_\(eu\)_firmware | 0 |
| siemens | ruggedcom_rm1224_lte\(4g\)_eu_firmware | 0 |
| Siemens | RUGGEDCOM RM1224 LTE(4G) NAM | 0 |
| siemens | scalance_mum856-1_\(row\)_firmware | 0 |
| siemens | scalance_m876-4_firmware | 0 |
…and 30 more
Exploit Intelligence
- CIRCL seen: CVE-2024-41978 (circl-sighting)
- https://cert-portal.siemens.com/productcert/html/ssa-087301.html (circl)
Timeline
- Aug 13, 2024 CVE Published
- Aug 13, 2024 EPSS Score
- Aug 13, 2024 PoC Published
- Aug 16, 2024 CVE Updated
- Sep 3, 2024 EPSS Score
- Sep 24, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 14, 2024 EPSS Score
- Nov 4, 2024 EPSS Score
- Nov 25, 2024 EPSS Score
- Dec 17, 2024 EPSS Score
- Jan 7, 2025 EPSS Score
References
- https://cert-portal.siemens.com/productcert/html/ssa-856475.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-357412.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-720392.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-921449.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-068047.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-784301.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-716317.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-659443.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-087301.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-417547.html advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-41978 advisory