VDB
ICSA-24-256-08
ICSA-24-256-08
PUBLISHED
CVSS 7.300000190734863 HIGH
A Socket.IO vulnerability affects multiple Siemens industrial products. This vulnerability consists of a specially crafted Socket.IO packet that triggers an uncaught exception on the Socket.IO server killing the Node.js process allowing a remote attacker to cause Denial-of-Service condition in the affected products. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Risk Scores
CVSS v3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SIMATIC PCS neo V4.1 | ||
| SIMATIC WinCC V7.4 | ||
| SIMATIC WinCC V7.5 | ||
| SIMATIC WinCC Runtime Professional V18 | ||
| SIMATIC WinCC Runtime Professional V17 | ||
| Data Flow Monitoring Industrial Edge Device User Interface (DFM IED UI) | ||
| SIMATIC PCS neo V5.0 | ||
| LiveTwin Industrial Edge app (6AV2170-0BL00-0AA0) | ||
| SIMATIC WinCC V8.0 | ||
| AI Model Deployer | ||
| TIA Administrator | ||
| SIMATIC WinCC Runtime Professional V19 |
Timeline
- Sep 10, 2024 CVE Published
- May 6, 2025 CVE Updated
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-773256.json advisory
- https://cert-portal.siemens.com/productcert/html/ssa-773256.html advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-256-08.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-08 advisory
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 url
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B url
- https://iehub.eu1.edge.siemens.cloud/ fix
- https://support.industry.siemens.com/cs/ww/en/view/109977244/ fix
- https://support.industry.siemens.com/cs/ww/en/view/109793460/ fix