North Korean APT Kimsuky aka Black Banshee – Active IOCs
July 31, 2024CISA Alerts Users of VMware ESXi Vulnerability Exploited in Ransomware Attacks
July 31, 2024North Korean APT Kimsuky aka Black Banshee – Active IOCs
July 31, 2024CISA Alerts Users of VMware ESXi Vulnerability Exploited in Ransomware Attacks
July 31, 2024Severity
High
Analysis Summary
CVE-2024-39869 CVSS:6.5
Siemens SINEMA Remote Connect Server is vulnerable to a denial of service, caused by improper check for unusual or exceptional conditions. By uploading a specially crafted certificate, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-35303 CVSS:7.8
Siemens Tecnomatix Plant Simulation could allow a remote attacker to execute arbitrary code on the system, caused by a type confusion vulnerability. By persuading a victim to parse specially crafted MODEL files, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVE-2024-35292 CVSS:8.2
Siemens SIMATIC could allow a remote attacker to obtain sensitive information, caused by using a predictable IP ID sequence number. By sending a specially crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information and caused a denial of service.
Impact
- Gain Access
- Denial of Service
Indicators of Compromise
CVE
- CVE-2024-39869
- CVE-2024-35303
- CVE-2024-35292
Affected Vendors
Affected Products
- Siemens SINEMA Remote Connect Server 3.2
- Siemens Tecnomatix Plant Simulation V2302
- Siemens Tecnomatix Plant Simulation V2404
- Siemens SIMATIC S7-200 SMART CPU CR40
- Siemens SIMATIC S7-200 SMART CPU CR60
- Siemens SIMATIC S7-200 SMART CPU SR20
Remediation
Refer to Siemens Security Advisory for patch, upgrade or suggested workaround information.