THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-32741

Reserved:2024-04-17
Published:2024-05-14
Updated:2024-05-15

Description

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to crack the password hash gains root access to the device.



CRITICAL: 10.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C

Problem types

CWE-259: Use of Hard-coded Password

Product status

Default status
unknown

Any version before V3.0
affected

References

https://cert-portal.siemens.com/productcert/html/ssa-273900.html

cve.org CVE-2024-32741

nvd.nist.gov CVE-2024-32741

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-32741