CVE-2024-21483

MEDIUM

SENTRON 7KM PAC3120 AC/DC, SENTRON 7KM PAC3120 DC, SENTRON 7KM PAC3...

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3120 DC (7KM3120-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 AC/DC (7KM3220-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 DC (7KM3220-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)). The read out protection of the internal flash of affected devices was not properly set at the end of the manufacturing process. An attacker with physical access to the device could read out the data.

References (1)

Core 1

Scores

CVSS v3 4.6
EPSS 0.0006
EPSS Percentile 19.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (4)
Siemens/SENTRON 7KM PAC3120 AC/DC V3.2.3 - V3.2.4
Siemens/SENTRON 7KM PAC3120 DC V3.2.3 - V3.2.4
Siemens/SENTRON 7KM PAC3220 AC/DC V3.2.3 - V3.2.4
Siemens/SENTRON 7KM PAC3220 DC V3.2.3 - V3.2.4
Published Mar 12, 2024
Tracked Since Feb 18, 2026