The vendor explicitly identifies these products as affected by this CVE.
- SIRIUS 3RK3 Modular Safety System (MSS)
- SIRIUS Safety Relays 3SK2
- Summary
- The affected devices do not require authentication to access critical resources. An attacker with network access could retrieve sensitive information from certain data records, including obfuscated safety passwords.
- Remediation
- Limit physical access to affected devices to trusted personnel
