ID

VAR-202412-3099


TITLE

Siemens Totally Integrated Automation Portal (TIA Portal) Buffer Overflow Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2024-48430

DESCRIPTION

Totally Integrated Automation Portal (TIA Portal) is an integrated automation platform that provides a full range of digital automation services from digital planning to integrated engineering and transparent operation. TIA Portal is designed to shorten time to market, improve factory production efficiency, and increase system flexibility. It includes innovative simulation tools, seamlessly integrated engineering functions, and transparent operation management, and is particularly suitable for system integrators, machine manufacturers, and factory operators. Siemens Totally Integrated Automation Portal (TIA Portal) has a buffer overflow vulnerability that can be exploited by unauthenticated remote attackers to execute arbitrary code.

Trust: 0.6

sources: CNVD: CNVD-2024-48430

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-48430

AFFECTED PRODUCTS

vendor:siemensmodel:totally integrated automation portalscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2024-48430

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2024-48430
value: HIGH

Trust: 0.6

CNVD: CNVD-2024-48430
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2024-48430

EXTERNAL IDS

db:CNVDid:CNVD-2024-48430

Trust: 0.6

sources: CNVD: CNVD-2024-48430

SOURCES

db:CNVDid:CNVD-2024-48430

LAST UPDATE DATE

2025-01-11T23:19:08.378000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-48430date:2024-12-17T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-48430date:2024-12-17T00:00:00