CVE-2024-54678
8.2Siemens · SIMATIC PCS neo, SIMATIC STEP 7, SIMATIC WinCC, SIMOCODE ES, SIMOTION SCOUT TIA, SINAMICS Startdrive, SIRIUS Safety ES
Multiple Siemens industrial software products are affected by a deserialization of untrusted data vulnerability that could lead to full system compromise.
Executive summary
A critical deserialization vulnerability in various Siemens SIMATIC and industrial automation software products presents a severe risk of unauthorized code execution and total system impact.
Vulnerability
This vulnerability is a deserialization of untrusted data flaw (CWE-502) that allows an attacker with local, low-privilege access and user interaction to achieve full system compromise. The CVSS 4.0 vector indicates that while local access is required, the integrity, availability, and confidentiality impacts are total.
Business impact
Successful exploitation of this flaw allows an attacker to execute arbitrary code with elevated privileges on systems running critical industrial automation software. This poses a significant threat to operational technology environments, potentially resulting in unauthorized process control, loss of production, or compromise of sensitive engineering data. Given the high severity, immediate remediation is required to prevent potential disruption to industrial processes.
Remediation
Immediate Action: Review the official Siemens Security Advisory (SSA-693808) and update all affected software components to the specified patched versions or higher as listed in the vendor documentation.
Proactive Monitoring: Monitor engineering workstations and server logs for signs of unauthorized process execution or unexpected binary loading events.
Compensating Controls: Implement strict access control policies to limit local user permissions and ensure that only authorized personnel can interact with industrial engineering software.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability represents a significant risk to industrial automation environments due to the potential for total system compromise. IT and OT administrators must prioritize the identification of affected Siemens installations and apply the necessary patches provided by the vendor. Failure to address this flaw could leave critical infrastructure exposed to sophisticated localized attacks.