CVE-2024-49775
published 2024-12-16CVE-2024-49775: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.52%
71.8th percentile
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions if operated in conjunction with UMC < V2.15), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions). Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component.
This could allow an unauthenticated remote attacker to execute arbitrary code.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | opcenter_execution_foundation | < V2501.0001 | V2501.0001 |
| siemens | opcenter_intelligence | < V2501.0001 | V2501.0001 |
| siemens | opcenter_quality | < V2512 | V2512 |
| siemens | opcenter_rdnl | < V2410 | V2410 |
| siemens | simatic_pcs_neo_v4.0 | < * | * |
| siemens | simatic_pcs_neo_v4.1 | < V4.1 Update 3 | V4.1 Update 3 |
| siemens | simatic_pcs_neo_v5.0 | < V5.0 Update 1 | V5.0 Update 1 |
| siemens | sinec_nms | < * | * |
| siemens | totally_integrated_automation_portal_v16 | < * | * |
| siemens | totally_integrated_automation_portal_v17 | < * | * |
| siemens | totally_integrated_automation_portal_v18 | < * | * |
| siemens | totally_integrated_automation_portal_v19 | < * | * |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor and alert on inbound connections to TCP ports 4002 and 4004 from unexpected or external IP addresses, as these are the UMC service ports targeted by this heap-based buffer overflow vulnerability. ↗
- →Port 4004 can be fully blocked if no RT server machines are present; any traffic observed on this port in such environments is anomalous and warrants investigation. ↗
- →The vulnerability is unauthenticated and network-reachable (CVSS:3.1/AV:N/AC:L/PR:N/UI:N); any unauthenticated connection attempts to UMC ports 4002/4004 from untrusted hosts should be treated as high-priority alerts. ↗
- ·SINEC NMS requires BOTH the application update (V3.0 SP2+) AND the UMC component update (V2.15+) to be remediated; updating only one is insufficient. ↗
- ·SIMATIC PCS neo V4.0 has no fix available; all versions remain vulnerable and only network-level mitigations (port filtering) apply. ↗
- ·All versions of TIA Portal V16 through V19 are listed as affected with no patched version indicated; rely on network-level controls for these products. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qc35-5wrm-x6wx: A vulnerability has been identified in Opcenter Execution Foundation (All versions), Opcenter Intelligence (All versions), Opcenter Quality (All versi
ghsa_unreviewed·2024-12-16
CVE-2024-49775 [CRITICAL] CWE-122 GHSA-qc35-5wrm-x6wx: A vulnerability has been identified in Opcenter Execution Foundation (All versions), Opcenter Intelligence (All versions), Opcenter Quality (All versi
A vulnerability has been identified in Opcenter Execution Foundation (All versions), Opcenter Intelligence (All versions), Opcenter Quality (All versions), Opcenter RDL (All versions), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions if operated in conjunction with UMC < V2.15), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions). Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component.
This could allow an unauthenticated
CISA ICS
Siemens User Management Component
cisa_ics·2024-12-19·CVSS 9.3
[CRITICAL] Siemens User Management Component
ICS Advisory
##
Siemens User Management Component
Release DateDecember 19, 2024
Alert CodeICSA-24-354-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: User Management Component (UMC)
- Vulnerability: Heap-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of thi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-16
Published