VDB
ICSA-25-254-04
ICSA-25-254-04
PUBLISHED
CVSS 3.0999999046325684 LOW
SINEC OS is affected by multiple vulnerabilities due to open UDP ports, which could allow an attacker to access non-sensitive information without authentication or potentially cause temporary denial of service. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Risk Scores
CVSS 3.1
3.0999999046325684
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| RUGGEDCOM RST2428P (6GK6242-6PA00) |
Timeline
- Sep 9, 2025 CVE Published
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-494539.json advisory
- https://cert-portal.siemens.com/productcert/html/ssa-494539.html advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-254-04.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-254-04 advisory
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 url
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B url