CVE-2024-39675 is a high-severity vulnerability affecting numerous RUGGEDCOM RMC30, RP110, RS400, RS401, RS416, RS910, and RS920 series devices, specifically serial devices running older firmware versions. The flaw allows the Modbus service to be improperly enabled in non-managed VLANs in certain configurations. With a CVSS score of 8.8, this vulnerability presents a significant risk, as an unauthenticated attacker on the adjacent network can achieve high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Siemens | RUGGEDCOM RMC30 | >= 0, < V4.3.10CNA affecteddefault unknown | |
| Siemens | RUGGEDCOM RMC30NC | >= 0, < V4.3.10CNA affecteddefault unknown | |
| Siemens | RUGGEDCOM RP110 | >= 0, < V4.3.10CNA affecteddefault unknown | |
| Siemens | RUGGEDCOM RP110NC | >= 0, < V4.3.10CNA affecteddefault unknown | |
| Siemens | RUGGEDCOM RS400 | >= 0, < V4.3.10CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.