Rewterz
North Korean APT Kimsuky aka Black Banshee – Active IOCs
July 31, 2024
Rewterz
CISA Alerts Users of VMware ESXi Vulnerability Exploited in Ransomware Attacks
July 31, 2024

ICS: Multiple Siemens Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-39869 CVSS:6.5

Siemens SINEMA Remote Connect Server is vulnerable to a denial of service, caused by improper check for unusual or exceptional conditions. By uploading a specially crafted certificate, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-35303 CVSS:7.8

Siemens Tecnomatix Plant Simulation could allow a remote attacker to execute arbitrary code on the system, caused by a type confusion vulnerability. By persuading a victim to parse specially crafted MODEL files, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2024-35292 CVSS:8.2

Siemens SIMATIC could allow a remote attacker to obtain sensitive information, caused by using a predictable IP ID sequence number. By sending a specially crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information and caused a denial of service.

Impact

  • Gain Access
  • Denial of Service

Indicators of Compromise

CVE

  • CVE-2024-39869
  • CVE-2024-35303
  • CVE-2024-35292

Affected Vendors

Siemens

Affected Products

  • Siemens SINEMA Remote Connect Server 3.2
  • Siemens Tecnomatix Plant Simulation V2302
  • Siemens Tecnomatix Plant Simulation V2404
  • Siemens SIMATIC S7-200 SMART CPU CR40
  • Siemens SIMATIC S7-200 SMART CPU CR60
  • Siemens SIMATIC S7-200 SMART CPU SR20

Remediation

Refer to Siemens Security Advisory for patch, upgrade or suggested workaround information.

CVE-2024-39869

CVE-2024-35303

CVE-2024-35292