CVE-2024-8751
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SICK AG | MSC800 | V1.0 <= <=V4.25 | affected |
| SICK AG | MSC800 | S1.0 <= <=S2.93.19 | affected |
| Endress+Hauser | MARSIC200 | all versions | affected |
| Endress+Hauser | MARSIC280 | all versions | affected |
| Endress+Hauser | MARSIC300 | all versions | affected |
| Endress+Hauser | MCS100FT | all versions | affected |
| Endress+Hauser | MCS200HW | all versions | affected |
| Endress+Hauser | MCS300P | all versions | affected |
| Endress+Hauser | MERCEM300Z | all versions | affected |
| Endress+Hauser | SAM800 | all versions | affected |
| Endress+Hauser | SIPROCESS | all versions | affected |
| Endress+Hauser | GMS800 | all versions | affected |
| Endress+Hauser | GMS800 FIDOR | all versions | affected |
| Endress+Hauser | GM32 | all versions | affected |
| Endress+Hauser | VICOTEC320 | all versions | affected |
| Endress+Hauser | MCU ETH-Service and Modbus-TCP Module | all versions | affected |
| Endress+Hauser | FLPS | all versions | affected |
| Endress+Hauser | MES1B B&B Converter | all versions | affected |
Weaknesses
- CWE-306: CWE-306 Missing Authentication for Critical Function
Workarounds
For Endress+Hauser MARSIC200, MARSIC280, MARSIC300, MCS100FT, MCS200HW, MCS300P, MERCEM300Z, SAM800, SIPROCESS, GMS800, GMS800 FIDOR, GM32, VICOTEC320, MCU ETH-Service and Modbus-TCP Module, FLPS, MES1B B&B Converter: Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The ”ICS-CERT recommended practices on Industrial Security” could help to implement the general security practices.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://sick.com/psirt
- https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
- https://www.first.org/cvss/calculator/3.1
- https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.pdf
- https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.pdf
- https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.json
- https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.json
- https://www.endress.com
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.