Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-8751

Quick assessment

Affected
SICK AG MSC800
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SICK MSC800是德国西克(SICK)公司的一款可编程逻辑控制器(PLC)。 SICK MSC800 4.26版本和SICK MSC800 LFT S2.93.20版本存在安全漏洞,该漏洞源于允许未经身份验证的攻击者通过Sopas ET修改产品的IP地址,从而导致拒绝服务。

CVSS 7.5 · High EPSS 0.93% · P59

Affected Version Matrix 18

VendorProduct Version RangeStatus
Endress+Hauser FLPS all versions affected
Endress+Hauser GM32 all versions affected
Endress+Hauser GMS800 all versions affected
Endress+Hauser GMS800 FIDOR all versions affected
Endress+Hauser MARSIC200 all versions affected
Endress+Hauser MARSIC280 all versions affected
Endress+Hauser MARSIC300 all versions affected
Endress+Hauser MCS100FT all versions affected
Endress+Hauser MCS200HW all versions affected
Endress+Hauser MCS300P all versions affected
Endress+Hauser MCU ETH-Service and Modbus-TCP Module all versions affected
Endress+Hauser MERCEM300Z all versions affected
Endress+Hauser MES1B B&B Converter all versions affected
Endress+Hauser SAM800 all versions affected
Endress+Hauser SIPROCESS all versions affected
Endress+Hauser VICOTEC320 all versions affected
SICK AG MSC800 V1.0≤ <=V4.25 affected
S1.0≤ <=S2.93.19 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-8751

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2024-8751
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
SICK MSC800 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SICK MSC800是德国西克(SICK)公司的一款可编程逻辑控制器(PLC)。 SICK MSC800 4.26版本和SICK MSC800 LFT S2.93.20版本存在安全漏洞,该漏洞源于允许未经身份验证的攻击者通过Sopas ET修改产品的IP地址,从而导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
SICK AG MSC800 V1.0 ~ <=V4.25 -
Endress+Hauser MARSIC200 all versions -
Endress+Hauser MARSIC280 all versions -
Endress+Hauser MARSIC300 all versions -
Endress+Hauser MCS100FT all versions -
Endress+Hauser MCS200HW all versions -
Endress+Hauser MCS300P all versions -
Endress+Hauser MERCEM300Z all versions -
Endress+Hauser SAM800 all versions -
Endress+Hauser SIPROCESS all versions -
Endress+Hauser GMS800 all versions -
Endress+Hauser GMS800 FIDOR all versions -
Endress+Hauser GM32 all versions -
Endress+Hauser VICOTEC320 all versions -
Endress+Hauser MCU ETH-Service and Modbus-TCP Module all versions -
Endress+Hauser FLPS all versions -
Endress+Hauser MES1B B&B Converter all versions -

II. Public POCs for CVE-2024-8751

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-8751

请登录查看更多情报信息。

Vendor Advisories for CVE-2024-8751 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2024-8751

No comments yet


Leave a comment