Siemens SIRIUS Safety Relays and Modular Safety Systems Weak Password Obfuscation Vulnerability

Vulnerability

A vulnerability exists in Siemens SIRIUS 3RK3 Modular Safety System (MSS) and SIRIUS Safety Relays 3SK2, all versions. The issue stems from weak password obfuscation, allowing an attacker with network access to retrieve and de-obfuscate safety passwords. These passwords are intended to protect against inadvertent operating errors but do not safeguard against malicious access attempts.

Impact

Exploitation of this vulnerability allows for the retrieval and de-obfuscation of safety passwords, which could lead to unauthorized operation by bypassing safeguards against inadvertent operating errors.

Remediation

Siemens is preparing fixed versions for these products. In the meantime, it is recommended to limit physical access to affected devices, ensure network isolation of the PROFINET interface from unauthorized systems, and follow Siemens' operational guidelines for Industrial Security.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.