CVE-2024-21483: Siemens Sentron 7km PAC3120 Ac/dc
Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3120 DC (7KM3120-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 AC/DC (7KM3220-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 DC (7KM3220-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)). The read out protection of the internal flash of affected devices was not properly set at the end of the manufacturing process. An attacker with physical access to the device could read out the data.
Affected products
- Siemens Sentron 7km PAC3120 Ac/dc: from V3.2.3, before V3.2.4 (fixed in V3.2.4)
- Siemens Sentron 7km PAC3120 DC: from V3.2.3, before V3.2.4 (fixed in V3.2.4)
- Siemens Sentron 7km PAC3220 Ac/dc: from V3.2.3, before V3.2.4 (fixed in V3.2.4)
- Siemens Sentron 7km PAC3220 DC: from V3.2.3, before V3.2.4 (fixed in V3.2.4)
Published 2024-03-12. Last modified 2026-06-17.