cbcvebase.
CVE-2024-33698
published 2024-09-10

CVE-2024-33698: A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions)…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.06%
60.9th percentile
A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions), SINEMA Remote Connect Client (All versions < V3.2 SP3), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 5), Totally Integrated Automation Portal (TIA Portal) V19 (All versions < V19 Update 3). Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code.

Affected

11 ranges
VendorProductVersion rangeFixed in
siemensopcenter_quality< V2406V2406
siemensopcenter_rdnl< V2410V2410
siemenssimatic_pcs_neo_v4.0< **
siemenssimatic_pcs_neo_v4.1< V4.1 Update 2V4.1 Update 2
siemenssimatic_pcs_neo_v5.0< V5.0 Update 1V5.0 Update 1
siemenssinec_nms< **
siemenssinema_remote_connect_client< V3.2 SP3V3.2 SP3
siemenstotally_integrated_automation_portal_v16< **
siemenstotally_integrated_automation_portal_v17< V17 Update 8V17 Update 8
siemenstotally_integrated_automation_portal_v18< V18 Update 5V18 Update 5
siemenstotally_integrated_automation_portal_v19< V19 Update 3V19 Update 3

Detection & IOCsextracted from sources · hover to see the quote

port4002
port4004
  • Monitor for unauthenticated inbound connections to TCP ports 4002 and 4004 on UMC hosts; unexpected sources may indicate exploitation attempts of the heap-based buffer overflow.
  • If no RT server machines are present in the environment, port 4004 should see zero legitimate traffic and any connection attempts should be treated as highly suspicious.
  • The vulnerability is exploitable by unauthenticated remote attackers with no user interaction required (CVSS AV:N/AC:L/PR:N/UI:N); prioritize detection of anomalous process behaviour on UMC hosts following network activity on ports 4002/4004.
  • ·The vulnerable component is the integrated UMC (User Management Component); patching requires updating UMC to V2.11.6 (SINEC NMS) or V2.13.1 (TIA Portal V18/V19 via TIA Portal V17 Update 8). Verify the UMC version specifically, not just the parent product version.
  • ·Several affected product lines (SIMATIC Information Server 2022/2024, SIMATIC PCS neo V4.0/V5.0, TIA Portal V16/V18) had no fix available at time of advisory publication; network-level port filtering of 4002/4004 is the primary mitigation for these.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.