{"api_version":"1","generated_at":"2026-07-23T12:57:28+00:00","cve":"CVE-2024-8751","urls":{"html":"https://cve.report/CVE-2024-8751","api":"https://cve.report/api/cve/CVE-2024-8751.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-8751","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-8751"},"summary":{"title":"CVE-2024-8751","description":"A vulnerability allows a remote unauthenticated attacker to modify the prod\nuct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.","state":"PUBLISHED","assigner":"SICK AG","published_at":"2024-09-12 22:15:02","updated_at":"2026-07-16 11:16:36"},"problem_types":["CWE-306","CWE-306 CWE-306 Missing Authentication for Critical Function"],"metrics":[{"version":"3.1","source":"psirt@sick.de","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.json","name":"https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.json","refsource":"psirt@sick.de","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.pdf","name":"https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.pdf","refsource":"psirt@sick.de","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.first.org/cvss/calculator/3.1","name":"https://www.first.org/cvss/calculator/3.1","refsource":"psirt@sick.de","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.endress.com","name":"https://www.endress.com","refsource":"psirt@sick.de","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://sick.com/psirt","name":"https://sick.com/psirt","refsource":"psirt@sick.de","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cisa.gov/resources-tools/resources/ics-recommended-practices","name":"https://www.cisa.gov/resources-tools/resources/ics-recommended-practices","refsource":"psirt@sick.de","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.json","name":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.json","refsource":"psirt@sick.de","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF","name":"https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF","refsource":"psirt@sick.de","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.pdf","name":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.pdf","refsource":"psirt@sick.de","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-8751","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8751","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Endress+Hauser","product":"MSC800","version":"affected V1.0 <=V4.25 custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"MSC800","version":"affected S1.0 <=S2.93.19 custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"MARSIC200","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"MARSIC280","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"MARSIC300","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"MCS100FT","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"MCS200HW","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"MCS300P","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"MERCEM300Z","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"SAM800","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"SIPROCESS","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"GMS800","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"GMS800 FIDOR","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"GM32","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"VICOTEC320","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"MCU ETH-Service and Modbus-TCP Module","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"FLPS","version":"affected all versions custom","platforms":[]},{"source":"CNA","vendor":"Endress+Hauser","product":"MES1B B&B Converter","version":"affected all versions custom","platforms":[]},{"source":"ADP","vendor":"sick","product":"msc800_firmware","version":"affected 1.0 4.25 custom","platforms":[]},{"source":"ADP","vendor":"sick","product":"msc800_firmware","version":"affected 1.0 s2.93.19 custom","platforms":[]}],"timeline":[{"source":"CNA","time":"2024-09-12T21:36:00.000Z","lang":"en","value":"1: Initial version"},{"source":"CNA","time":"2026-07-16T10:00:00.000Z","lang":"en","value":"2: Added more products"}],"solutions":[{"source":"CNA","title":"","value":"For Endress+Hauser MSC800FT: Customers who use the version <=V4.25 are strongly recommended to upgrade to the latest\nrelease V4.26","time":"","lang":"en"},{"source":"CNA","title":"","value":"For Endress+Hauser MSC800FT: Customers who use the version <=S2.93.19 are strongly recommended to upgrade to the\nlatest release S2.93.20.","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"For Endress+Hauser MARSIC200, MARSIC280, MARSIC300, MCS100FT, MCS200HW, MCS300P, MERCEM300Z, SAM800, SIPROCESS, GMS800, GMS800 FIDOR, GM32, VICOTEC320, MCU ETH-Service and Modbus-TCP Module, FLPS, MES1B B&B Converter:  Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The ”ICS-CERT recommended practices on Industrial Security” could help to implement the general security practices.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2024","cve_id":"8751","cve":"CVE-2024-8751","epss":"0.009260000","percentile":"0.567260000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:34"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"affected":[{"cpes":["cpe:2.3:o:sick:msc800_firmware:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","product":"msc800_firmware","vendor":"sick","versions":[{"lessThanOrEqual":"4.25","status":"affected","version":"1.0","versionType":"custom"},{"lessThanOrEqual":"s2.93.19","status":"affected","version":"1.0","versionType":"custom"}]}],"metrics":[{"other":{"content":{"id":"CVE-2024-8751","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2024-09-13T13:53:13.856056Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2024-09-13T14:02:19.375Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"affected","product":"MSC800","vendor":"Endress+Hauser","versions":[{"lessThanOrEqual":"<=V4.25","status":"affected","version":"V1.0","versionType":"custom"},{"lessThanOrEqual":"<=S2.93.19","status":"affected","version":"S1.0","versionType":"custom"}]},{"defaultStatus":"affected","product":"MARSIC200","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"MARSIC280","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"MARSIC300","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"MCS100FT","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"MCS200HW","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"MCS300P","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"MERCEM300Z","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"SAM800","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"SIPROCESS","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"GMS800","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"GMS800 FIDOR","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"GM32","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"VICOTEC320","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"MCU ETH-Service and Modbus-TCP Module","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"FLPS","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]},{"defaultStatus":"affected","product":"MES1B B&B Converter","vendor":"Endress+Hauser","versions":[{"status":"affected","version":"all versions","versionType":"custom"}]}],"datePublic":"2024-09-12T21:33:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"A vulnerability allows a remote unauthenticated attacker to modify the prod\nuct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.&nbsp;<br>"}],"value":"A vulnerability allows a remote unauthenticated attacker to modify the prod\nuct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-16T09:48:36.996Z","orgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","shortName":"SICK AG"},"references":[{"tags":["x_SICK PSIRT Website"],"url":"https://sick.com/psirt"},{"tags":["x_SICK Operating Guidelines"],"url":"https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF"},{"tags":["x_ICS-CERT recommended practices on Industrial Security"],"url":"https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"},{"tags":["x_CVSS v3.1 Calculator"],"url":"https://www.first.org/cvss/calculator/3.1"},{"tags":["vendor-advisory"],"url":"https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.pdf"},{"tags":["vendor-advisory"],"url":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.pdf"},{"tags":["x_The canonical URL"],"url":"https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.json"},{"tags":["x_The canonical URL"],"url":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.json"},{"tags":["x_Endress+Hauser"],"url":"https://www.endress.com"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"For Endress+Hauser MSC800FT: Customers who use the version &lt;=V4.25 are strongly recommended to upgrade to the latest\nrelease V4.26\n\n<br>"}],"value":"For Endress+Hauser MSC800FT: Customers who use the version <=V4.25 are strongly recommended to upgrade to the latest\nrelease V4.26"},{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"For Endress+Hauser MSC800FT: Customers who use the version &lt;=S2.93.19 are strongly recommended to upgrade to the\nlatest release S2.93.20.\n\n<br>"}],"value":"For Endress+Hauser MSC800FT: Customers who use the version <=S2.93.19 are strongly recommended to upgrade to the\nlatest release S2.93.20."}],"source":{"discovery":"INTERNAL"},"timeline":[{"lang":"en","time":"2024-09-12T21:36:00.000Z","value":"1: Initial version"},{"lang":"en","time":"2026-07-16T10:00:00.000Z","value":"2: Added more products"}],"title":"CVE-2024-8751","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>For Endress+Hauser&nbsp;MARSIC200, MARSIC280, MARSIC300, MCS100FT, MCS200HW, MCS300P, MERCEM300Z, SAM800, SIPROCESS, GMS800, GMS800 FIDOR, GM32, VICOTEC320, MCU ETH-Service and Modbus-TCP Module, FLPS, MES1B B&amp;B Converter:&nbsp; Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The ”ICS-CERT recommended practices on Industrial Security” could help to implement the general security practices.</p>"}],"value":"For Endress+Hauser MARSIC200, MARSIC280, MARSIC300, MCS100FT, MCS200HW, MCS300P, MERCEM300Z, SAM800, SIPROCESS, GMS800, GMS800 FIDOR, GM32, VICOTEC320, MCU ETH-Service and Modbus-TCP Module, FLPS, MES1B B&B Converter:  Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The ”ICS-CERT recommended practices on Industrial Security” could help to implement the general security practices."}],"x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","assignerShortName":"SICK AG","cveId":"CVE-2024-8751","datePublished":"2024-09-12T21:38:37.516Z","dateReserved":"2024-09-12T13:17:03.176Z","dateUpdated":"2026-07-16T09:48:36.996Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2024-09-12 22:15:02","lastModifiedDate":"2026-07-16 11:16:36","problem_types":["CWE-306","CWE-306 CWE-306 Missing Authentication for Critical Function"],"metrics":{"cvssMetricV31":[{"source":"psirt@sick.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-13T13:53:13.856056Z","id":"CVE-2024-8751","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"8751","Ordinal":"1","Title":"CVE-2024-8751","CVE":"CVE-2024-8751","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"8751","Ordinal":"1","NoteData":"A vulnerability allows a remote unauthenticated attacker to modify the prod\nuct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.","Type":"Description","Title":"CVE-2024-8751"}]}}}