A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not encrypt data in transit. An attacker with network access could eavesdrop the connection and retrieve sensitive information, including obfuscated safety passwords.
Metrics
Affected Vendors & Products
References
History
Tue, 13 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 May 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not encrypt data in transit. An attacker with network access could eavesdrop the connection and retrieve sensitive information, including obfuscated safety passwords. | |
Weaknesses | CWE-311 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: siemens
Published: 2025-05-13T09:38:30.444Z
Updated: 2025-05-13T19:02:28.353Z
Reserved: 2025-01-16T16:19:30.407Z
Link: CVE-2025-24008

Updated: 2025-05-13T19:02:03.262Z

Status : Awaiting Analysis
Published: 2025-05-13T10:15:22.943
Modified: 2025-05-13T19:35:18.080
Link: CVE-2025-24008

No data.