ICSA-24-347-05
Affected products do not properly sanitize user-controllable input when parsing files. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected application. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. Siemens has released products based on the Totally Integrated Automation Portal (TIA Portal) V20 which are not affected by CVE-2024-49849. See the chapter "Additional Information" below for more details.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SIMATIC STEP 7 V19 | ||
| SIMATIC STEP 7 Safety V19 | ||
| SIMATIC S7-PLCSIM V17 | ||
| SIMOCODE ES V16 | ||
| SIMATIC WinCC Unified V19 | ||
| SIMATIC STEP 7 Safety V16 | ||
| SIMATIC WinCC V17 | ||
| SIMATIC STEP 7 Safety V17 | ||
| SIMATIC STEP 7 Safety V18 | ||
| SIMATIC S7-PLCSIM V16 | ||
| SIMATIC STEP 7 V18 | ||
| SIMATIC WinCC V16 | ||
| SIMATIC STEP 7 V16 | ||
| SIMATIC WinCC Unified V18 | ||
| SIMATIC WinCC Unified V17 | ||
| SIMATIC WinCC V19 | ||
| SIMATIC STEP 7 V17 | ||
| SIMATIC WinCC Unified V16 | ||
| SIMATIC WinCC V18 | ||
| SIMOCODE ES V17 |
Timeline
- Dec 10, 2024 CVE Published
- Aug 12, 2025 CVE Updated
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-800126.json advisory
- https://cert-portal.siemens.com/productcert/html/ssa-800126.html advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-347-05.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-347-05 advisory
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 url
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B url
- https://support.industry.siemens.com/cs/ww/en/view/109925643/ fix
- https://support.industry.siemens.com/cs/ww/en/view/109989067/ fix