{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-8751","assignerOrgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","state":"PUBLISHED","assignerShortName":"SICK AG","dateReserved":"2024-09-12T13:17:03.176Z","datePublished":"2024-09-12T21:38:37.516Z","dateUpdated":"2026-07-24T12:01:28.194Z"},"containers":{"cna":{"providerMetadata":{"orgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","shortName":"SICK AG","dateUpdated":"2026-07-24T12:01:28.194Z"},"title":"CVE-2024-8751","datePublic":"2024-09-12T21:33:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function","type":"CWE"}]}],"affected":[{"vendor":"SICK AG","product":"MSC800","versions":[{"status":"affected","version":"V1.0","lessThanOrEqual":"<=V4.25","versionType":"custom"},{"status":"affected","version":"S1.0","lessThanOrEqual":"<=S2.93.19","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"MARSIC200","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"MARSIC280","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"MARSIC300","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"MCS100FT","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"MCS200HW","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"MCS300P","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"MERCEM300Z","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"SAM800","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"SIPROCESS","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"GMS800","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"GMS800 FIDOR","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"GM32","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"VICOTEC320","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"MCU ETH-Service and Modbus-TCP Module","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"FLPS","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"Endress+Hauser","product":"MES1B B&B Converter","versions":[{"status":"affected","version":"all versions","versionType":"custom"}],"defaultStatus":"affected"}],"descriptions":[{"lang":"en","value":"A vulnerability allows a remote unauthenticated attacker to modify the prod\nuct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.","supportingMedia":[{"type":"text/html","base64":false,"value":"A vulnerability allows a remote unauthenticated attacker to modify the prod\nuct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.&nbsp;<br>"}]}],"references":[{"url":"https://sick.com/psirt","tags":["x_SICK PSIRT Website"]},{"url":"https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF","tags":["x_SICK Operating Guidelines"]},{"url":"https://www.cisa.gov/resources-tools/resources/ics-recommended-practices","tags":["x_ICS-CERT recommended practices on Industrial Security"]},{"url":"https://www.first.org/cvss/calculator/3.1","tags":["x_CVSS v3.1 Calculator"]},{"url":"https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.pdf","tags":["vendor-advisory"]},{"url":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.pdf","tags":["vendor-advisory"]},{"url":"https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.json","tags":["x_The canonical URL"]},{"url":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.json","tags":["x_The canonical URL"]},{"url":"https://www.endress.com","tags":["x_Endress+Hauser"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseSeverity":"HIGH","baseScore":7.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}}],"workarounds":[{"lang":"en","value":"For Endress+Hauser MARSIC200, MARSIC280, MARSIC300, MCS100FT, MCS200HW, MCS300P, MERCEM300Z, SAM800, SIPROCESS, GMS800, GMS800 FIDOR, GM32, VICOTEC320, MCU ETH-Service and Modbus-TCP Module, FLPS, MES1B B&B Converter:  Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The ”ICS-CERT recommended practices on Industrial Security” could help to implement the general security practices.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>For Endress+Hauser&nbsp;MARSIC200, MARSIC280, MARSIC300, MCS100FT, MCS200HW, MCS300P, MERCEM300Z, SAM800, SIPROCESS, GMS800, GMS800 FIDOR, GM32, VICOTEC320, MCU ETH-Service and Modbus-TCP Module, FLPS, MES1B B&amp;B Converter:&nbsp; Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The ”ICS-CERT recommended practices on Industrial Security” could help to implement the general security practices.</p>"}]}],"solutions":[{"lang":"en","value":"For Endress+Hauser MSC800FT: Customers who use the version <=V4.25 are strongly recommended to upgrade to the latest\nrelease V4.26","supportingMedia":[{"type":"text/html","base64":false,"value":"For Endress+Hauser MSC800FT: Customers who use the version &lt;=V4.25 are strongly recommended to upgrade to the latest\nrelease V4.26\n\n<br>"}]},{"lang":"en","value":"For Endress+Hauser MSC800FT: Customers who use the version <=S2.93.19 are strongly recommended to upgrade to the\nlatest release S2.93.20.","supportingMedia":[{"type":"text/html","base64":false,"value":"For Endress+Hauser MSC800FT: Customers who use the version &lt;=S2.93.19 are strongly recommended to upgrade to the\nlatest release S2.93.20.\n\n<br>"}]}],"timeline":[{"time":"2024-09-12T21:36:00.000Z","lang":"en","value":"1: Initial version"},{"time":"2026-07-16T10:00:00.000Z","lang":"en","value":"2: Added more products"}],"source":{"discovery":"INTERNAL"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"affected":[{"vendor":"sick","product":"msc800_firmware","cpes":["cpe:2.3:o:sick:msc800_firmware:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1.0","status":"affected","lessThanOrEqual":"4.25","versionType":"custom"},{"version":"1.0","status":"affected","lessThanOrEqual":"s2.93.19","versionType":"custom"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-13T13:53:13.856056Z","id":"CVE-2024-8751","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-13T14:02:19.375Z"}}]}}