CVE-2025-40946
CVE-2025-40946
A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 110 TL3 (All versions), blueplanet 125 NX3 M10 (All versions), blueplanet 125 TL3 (All versions), blueplanet 125 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 137 TL3 (All versions), blueplanet 150 TL3 (All versions), blueplanet 150 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 155 TL3 (All versions), blueplanet 155 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 165 TL3 (All versions), blueplanet 165 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 25.0 NX3-33.0 NX3 (All versions), blueplanet 3.0 NX3-20.0 NX3 (All versions), blueplanet 3.0 TL3-60.0 TL3 (All versions), blueplanet 3.0-5.0 NX1 (All versions), blueplanet 360 NX3 M6 (All versions), blueplanet 50.0 NX3-60.0 NX3 (All versions), blueplanet 87.0 TL3 (All versions), blueplanet 87.0 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 92.0 TL3 (All versions), blueplanet 92.0 TL3 GEN2 (All versions < V6.1.4.9), blueplanet gridsave 110 TL3-S (All versions < V3.91), blueplanet gridsave 137 TL3-S (All versions < V3.91), blueplanet gridsave 92.0 TL3-S (All versions < V3.91), blueplanet hybrid 10.0 TL3 (All versions), blueplanet hybrid 6.0 NH3-12.0 NH3 (All versions). A CRC16-based algorithm for generating Technical Service credentials could allow an attacker to derive the credentials from the devices serial number and misuse them to gain unauthorized access.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Siemens · blueplanet 100 NX3 M8Siemens · blueplanet 100 TL3 GEN2Siemens · blueplanet 105 TL3Siemens · blueplanet 105 TL3 GEN2Siemens · blueplanet 110 TL3Siemens · blueplanet 125 NX3 M10Siemens · blueplanet 125 TL3Siemens · blueplanet 125 TL3 GEN2Siemens · blueplanet 137 TL3Siemens · blueplanet 150 TL3Siemens · blueplanet 150 TL3 GEN2Siemens · blueplanet 155 TL3Siemens · blueplanet 155 TL3 GEN2Siemens · blueplanet 165 TL3Siemens · blueplanet 165 TL3 GEN2Siemens · blueplanet 25.0 NX3-33.0 NX3Siemens · blueplanet 3.0-5.0 NX1Siemens · blueplanet 3.0 NX3-20.0 NX3Siemens · blueplanet 3.0 TL3-60.0 TL3Siemens · blueplanet 360 NX3 M6Siemens · blueplanet 50.0 NX3-60.0 NX3Siemens · blueplanet 87.0 TL3Siemens · blueplanet 87.0 TL3 GEN2Siemens · blueplanet 92.0 TL3Siemens · blueplanet 92.0 TL3 GEN2Siemens · blueplanet gridsave 110 TL3-SSiemens · blueplanet gridsave 137 TL3-SSiemens · blueplanet gridsave 92.0 TL3-SSiemens · blueplanet hybrid 10.0 TL3Siemens · blueplanet hybrid 6.0 NH3-12.0 NH3Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →