CVE-2025-24510: Siemens Ms/tp Point Pickup Module

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices improperly handle specific incoming BACnet MSTP messages. This could allow an attacker residing in the same BACnet network to send a specially crafted MSTP message that results in a denial of service condition of the targeted device. A power cycle is required to restore the device's normal operation.

Affected products

  • Siemens Ms/tp Point Pickup Module: any version

Published 2025-05-13. Last modified 2026-06-17.