CVE-2024-41798: Siemens Sentron 7km PAC3200

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from administrative access via Modbus TCP interface. Attackers with access to the Modbus TCP interface could easily bypass this protection by brute-force attacks or by sniffing the Modbus clear text communication.

Affected products

  • Siemens Sentron 7km PAC3200: any version
  • Siemens Sentron PAC3200: any version

Published 2024-10-08. Last modified 2026-06-17.