cbcvebase.
CVE-2024-49775
published 2024-12-16

CVE-2024-49775: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter…

PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.52%
71.8th percentile
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions if operated in conjunction with UMC < V2.15), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions). Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code.

Affected

12 ranges
VendorProductVersion rangeFixed in
siemensopcenter_execution_foundation< V2501.0001V2501.0001
siemensopcenter_intelligence< V2501.0001V2501.0001
siemensopcenter_quality< V2512V2512
siemensopcenter_rdnl< V2410V2410
siemenssimatic_pcs_neo_v4.0< **
siemenssimatic_pcs_neo_v4.1< V4.1 Update 3V4.1 Update 3
siemenssimatic_pcs_neo_v5.0< V5.0 Update 1V5.0 Update 1
siemenssinec_nms< **
siemenstotally_integrated_automation_portal_v16< **
siemenstotally_integrated_automation_portal_v17< **
siemenstotally_integrated_automation_portal_v18< **
siemenstotally_integrated_automation_portal_v19< **

Detection & IOCsextracted from sources · hover to see the quote

port4002
port4004
  • Monitor and alert on inbound connections to TCP ports 4002 and 4004 from unexpected or external IP addresses, as these are the UMC service ports targeted by this heap-based buffer overflow vulnerability.
  • Port 4004 can be fully blocked if no RT server machines are present; any traffic observed on this port in such environments is anomalous and warrants investigation.
  • The vulnerability is unauthenticated and network-reachable (CVSS:3.1/AV:N/AC:L/PR:N/UI:N); any unauthenticated connection attempts to UMC ports 4002/4004 from untrusted hosts should be treated as high-priority alerts.
  • ·SINEC NMS requires BOTH the application update (V3.0 SP2+) AND the UMC component update (V2.15+) to be remediated; updating only one is insufficient.
  • ·SIMATIC PCS neo V4.0 has no fix available; all versions remain vulnerable and only network-level mitigations (port filtering) apply.
  • ·All versions of TIA Portal V16 through V19 are listed as affected with no patched version indicated; rely on network-level controls for these products.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.