A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted between the device and the user can be obtained by an attacker in a privileged network position. The security vulnerability can be exploited by an attacker in a privileged network position which allows eavesdropping the communication between the affected device and the user. The user must invoke a session. Successful exploitation of the vulnerability compromises confidentiality of the data transmitted.
2019-06-12T14:29:04.510
2024-11-21T04:20:10.120
Modified
CVSSv3.0: 5.3 (MEDIUM)
AV:N/AC:H/Au:N/C:P/I:N/A:N
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | siemens | simatic_mv420_firmware | * | Yes |
Hardware | siemens | simatic_mv420 | - | No |
Operating System | siemens | simatic_mv440_firmware | * | Yes |
Hardware | siemens | simatic_mv440 | - | No |