The vendor explicitly identifies these products as affected by this CVE.
- SENTRON 7KM PAC3200
- Summary
- Affected devices only provide a 4-digit PIN to protect from administrative access via Modbus TCP interface. Attackers with access to the Modbus TCP interface could easily bypass this protection by brute-force attacks or by sniffing the Modbus clear text communication.
- Remediation
- Consider the PIN as protection against unauthorized operation (i.e., protection against inadvertent operating errors), not as protection against malicious access attempts, such as through brute-force attacks; for details see the FAQ article at https://support.industry.siemens.com/cs/ww/en/view/109975235/
