CVE-2025-24007 Details
Description
A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). Affected devices only provide weak password obfuscation. An attacker with network access could retrieve and de-obfuscate the safety password used for protection against inadvertent operating errors.
A vulnerability exists in Siemens SIRIUS 3RK3 Modular Safety System (MSS) and SIRIUS Safety Relays 3SK2, all versions. The issue stems from weak password obfuscation, allowing an attacker with network access to retrieve and de-obfuscate safety passwords. These passwords are intended to protect against inadvertent operating errors but do not safeguard against malicious access attempts.
Siemens is preparing fixed versions for these products. In the meantime, it is recommended to limit physical access to affected devices, ensure network isolation of the PROFINET interface from unauthorized systems, and follow Siemens' operational guidelines for Industrial Security.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2025CISA-ADP
Assessed May 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-222768.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siemens SIRIUS 3RK3 Modular Safety System | All versions |
CPE
Remediation
| |
| Siemens SIRIUS 3SK2 Safety Relays | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2025 | New CVE Received | [email protected] |
Volerion