目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

CVE-2024-30191— Siemens SCALANCE W700产品系列安全漏洞

CVSS 8.4 · High EPSS 0.09% · P25
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2024-30191の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
N/A
ソース: NVD (National Vulnerability Database)
脆弱性説明
A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0), SCALANCE WAM766-1 (EU) (6GK5766-1GE00-7DA0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0), SCALANCE WAM766-1 EEC (EU) (6GK5766-1GE00-7TA0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0), SCALANCE WUM766-1 (EU) (6GK5766-1GE00-3DA0), SCALANCE WUM766-1 (US) (6GK5766-1GE00-3DB0). This CVE refers to Scenario 3 "Override client’s security context" of CVE-2022-47522. Affected devices can be tricked into associating a newly negotiated, attacker-controlled, security context with frames belonging to a victim. This could allow a physically proximate attacker to decrypt frames meant for the victim.
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
使用欺骗进行的认证绕过
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
Siemens SCALANCE W700产品系列安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Siemens SCALANCE是德国西门子(Siemens)公司的一系列以太网交换机。可连接到工业控制系统 (ICS) 设备,包括可编程逻辑控制器 (PLC) 和人机界面 (HMI) 系统。 Siemens SCALANCE W700产品系列存在安全漏洞,该漏洞源于受影响的设备可能被欺骗,从而数据被窃取等。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
SiemensSCALANCE W1748-1 M12 0 ~ * -
SiemensSCALANCE W1748-1 M12 0 ~ * -
SiemensSCALANCE W1788-1 M12 0 ~ * -
SiemensSCALANCE W1788-2 EEC M12 0 ~ * -
SiemensSCALANCE W1788-2 M12 0 ~ * -
SiemensSCALANCE W1788-2IA M12 0 ~ * -
SiemensSCALANCE W721-1 RJ45 0 ~ * -
SiemensSCALANCE W721-1 RJ45 0 ~ * -
SiemensSCALANCE W722-1 RJ45 0 ~ * -
SiemensSCALANCE W722-1 RJ45 0 ~ * -
SiemensSCALANCE W722-1 RJ45 0 ~ * -
SiemensSCALANCE W734-1 RJ45 0 ~ * -
SiemensSCALANCE W734-1 RJ45 0 ~ * -
SiemensSCALANCE W734-1 RJ45 0 ~ * -
SiemensSCALANCE W734-1 RJ45 (USA) 0 ~ * -
SiemensSCALANCE W738-1 M12 0 ~ * -
SiemensSCALANCE W738-1 M12 0 ~ * -
SiemensSCALANCE W748-1 M12 0 ~ * -
SiemensSCALANCE W748-1 M12 0 ~ * -
SiemensSCALANCE W748-1 RJ45 0 ~ * -
SiemensSCALANCE W748-1 RJ45 0 ~ * -
SiemensSCALANCE W761-1 RJ45 0 ~ * -
SiemensSCALANCE W761-1 RJ45 0 ~ * -
SiemensSCALANCE W774-1 M12 EEC 0 ~ * -
SiemensSCALANCE W774-1 M12 EEC 0 ~ * -
SiemensSCALANCE W774-1 RJ45 0 ~ * -
SiemensSCALANCE W774-1 RJ45 0 ~ * -
SiemensSCALANCE W774-1 RJ45 0 ~ * -
SiemensSCALANCE W774-1 RJ45 0 ~ * -
SiemensSCALANCE W774-1 RJ45 (USA) 0 ~ * -
SiemensSCALANCE W778-1 M12 0 ~ * -
SiemensSCALANCE W778-1 M12 0 ~ * -
SiemensSCALANCE W778-1 M12 EEC 0 ~ * -
SiemensSCALANCE W778-1 M12 EEC (USA) 0 ~ * -
SiemensSCALANCE W786-1 RJ45 0 ~ * -
SiemensSCALANCE W786-1 RJ45 0 ~ * -
SiemensSCALANCE W786-2 RJ45 0 ~ * -
SiemensSCALANCE W786-2 RJ45 0 ~ * -
SiemensSCALANCE W786-2 RJ45 0 ~ * -
SiemensSCALANCE W786-2 SFP 0 ~ * -
SiemensSCALANCE W786-2 SFP 0 ~ * -
SiemensSCALANCE W786-2IA RJ45 0 ~ * -
SiemensSCALANCE W786-2IA RJ45 0 ~ * -
SiemensSCALANCE W788-1 M12 0 ~ * -
SiemensSCALANCE W788-1 M12 0 ~ * -
SiemensSCALANCE W788-1 RJ45 0 ~ * -
SiemensSCALANCE W788-1 RJ45 0 ~ * -
SiemensSCALANCE W788-2 M12 0 ~ * -
SiemensSCALANCE W788-2 M12 0 ~ * -
SiemensSCALANCE W788-2 M12 EEC 0 ~ * -
SiemensSCALANCE W788-2 M12 EEC 0 ~ * -
SiemensSCALANCE W788-2 M12 EEC 0 ~ * -
SiemensSCALANCE W788-2 RJ45 0 ~ * -
SiemensSCALANCE W788-2 RJ45 0 ~ * -
SiemensSCALANCE W788-2 RJ45 0 ~ * -
SiemensSCALANCE WAM763-1 0 ~ * -
SiemensSCALANCE WAM766-1 (EU) 0 ~ * -
SiemensSCALANCE WAM766-1 (US) 0 ~ * -
SiemensSCALANCE WAM766-1 EEC (EU) 0 ~ * -
SiemensSCALANCE WAM766-1 EEC (US) 0 ~ * -
SiemensSCALANCE WUM763-1 0 ~ * -
SiemensSCALANCE WUM763-1 0 ~ * -
SiemensSCALANCE WUM766-1 (EU) 0 ~ * -
SiemensSCALANCE WUM766-1 (US) 0 ~ * -

II. CVE-2024-30191の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2024-30191のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Siemens · 2024-04-09 · 8 CVEs total

CVE-2024-262757.8 HIGHSiemens Parasolid 缓冲区错误漏洞
CVE-2024-319787.6 HIGHSiemens SINEC NMS 路径遍历漏洞
CVE-2023-508216.2 MEDIUMSiemens SIMATIC PCS 7 安全漏洞
CVE-2024-301896.1 MEDIUMSiemens SCALANCE W700产品系列安全漏洞
CVE-2024-301906.1 MEDIUMSiemens SCALANCE W700产品系列安全漏洞
CVE-2024-262763.3 LOWSiemens Parasolid 安全漏洞
CVE-2024-262773.3 LOWSiemens Parasolid 代码问题漏洞

IV. 関連脆弱性

V. CVE-2024-30191へのコメント

まだコメントはありません


コメントを残す