ID

VAR-202412-0387


CVE

CVE-2024-52051


TITLE

Siemens Engineering Platforms Local Arbitrary Code Execution Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2024-47913

DESCRIPTION

A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17 (All versions), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified V17 (All versions), SIMATIC WinCC Unified V18 (All versions), SIMATIC WinCC Unified V19 (All versions), SIMATIC WinCC V17 (All versions), SIMATIC WinCC V18 (All versions), SIMATIC WinCC V19 (All versions), SIMOCODE ES V17 (All versions), SIMOCODE ES V18 (All versions), SIMOCODE ES V19 (All versions), SIMOTION SCOUT TIA V5.4 SP3 (All versions), SIMOTION SCOUT TIA V5.5 SP1 (All versions), SIMOTION SCOUT TIA V5.6 SP1 (All versions), SINAMICS Startdrive V17 (All versions), SINAMICS Startdrive V18 (All versions), SINAMICS Startdrive V19 (All versions), SIRIUS Safety ES V17 (TIA Portal) (All versions), SIRIUS Safety ES V18 (TIA Portal) (All versions), SIRIUS Safety ES V19 (TIA Portal) (All versions), SIRIUS Soft Starter ES V17 (TIA Portal) (All versions), SIRIUS Soft Starter ES V18 (TIA Portal) (All versions), SIRIUS Soft Starter ES V19 (TIA Portal) (All versions), TIA Portal Cloud V17 (All versions), TIA Portal Cloud V18 (All versions), TIA Portal Cloud V19 (All versions). The affected devices do not properly sanitize user-controllable input when parsing user settings. This could allow an attacker to locally execute arbitrary commands in the host operating system with the privileges of the user. Totally Integrated Automation Portal (TIA Portal) is a PC software that provides the full range of Siemens digital automation services, from digital planning, integrated engineering to transparent operation

Trust: 1.44

sources: NVD: CVE-2024-52051 // CNVD: CNVD-2024-47913

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-47913

AFFECTED PRODUCTS

vendor:siemensmodel:totally integrated automation portalscope:eqversion:v17

Trust: 0.6

vendor:siemensmodel:totally integrated automation portalscope:eqversion:v18

Trust: 0.6

vendor:siemensmodel:totally integrated automation portalscope:eqversion:v19

Trust: 0.6

vendor:siemensmodel:simatic s7-plcsimscope:eqversion:v17

Trust: 0.6

vendor:siemensmodel:simatic s7-plcsimscope:eqversion:v18

Trust: 0.6

sources: CNVD: CNVD-2024-47913

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2024-52051
value: HIGH

Trust: 1.0

CNVD: CNVD-2024-47913
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2024-47913
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

productcert@siemens.com: CVE-2024-52051
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.3
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2024-47913 // NVD: CVE-2024-52051

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.0

sources: NVD: CVE-2024-52051

PATCH

title:Patch for Siemens Engineering Platforms Local Arbitrary Code Execution Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/639421

Trust: 0.6

sources: CNVD: CNVD-2024-47913

EXTERNAL IDS

db:NVDid:CVE-2024-52051

Trust: 1.6

db:SIEMENSid:SSA-392859

Trust: 1.6

db:CNVDid:CNVD-2024-47913

Trust: 0.6

sources: CNVD: CNVD-2024-47913 // NVD: CVE-2024-52051

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-392859.html

Trust: 1.6

sources: CNVD: CNVD-2024-47913 // NVD: CVE-2024-52051

SOURCES

db:CNVDid:CNVD-2024-47913
db:NVDid:CVE-2024-52051

LAST UPDATE DATE

2024-12-13T19:23:49.159000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-47913date:2024-12-12T00:00:00
db:NVDid:CVE-2024-52051date:2024-12-10T14:30:44.957

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-47913date:2024-12-12T00:00:00
db:NVDid:CVE-2024-52051date:2024-12-10T14:30:44.957