PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-6876 CODESYS GmbH CVE debrief

CVE-2024-6876 is a medium-severity out-of-bounds read vulnerability in the OSCAT Basic Library, published by CISA on 2024-11-21. The flaw allows a local, unprivileged attacker to access limited internal PLC data and potentially crash the affected service. The vulnerability affects CODESYS OSCAT Basic Library version 3.3.5.0 and earlier versions of the oscat.de OSCAT Basic Library (<=3.3.5 and <=335). CODESYS GmbH has released version 3.3.5.0 to address this issue. Users must update the library in the Library Manager, then perform a download or online change to update the PLC application and rebuild the boot application. As a workaround without updating, validate all values before passing to affected functions—specifically blocking negative values as parameters to MONTH_TO_STRING.

Vendor
CODESYS GmbH
Product
CODESYS OSCAT Basic Library
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-21
Original CVE updated
2024-11-21
Advisory published
2024-11-21
Advisory updated
2024-11-21

Who should care

Industrial control system operators, OT security teams, and engineers using CODESYS development environments with OSCAT Basic Library should prioritize this update. Organizations with PLCs running affected library versions in production environments face risk of service disruption and limited data exposure from local access.

Technical summary

The OSCAT Basic Library contains an out-of-bounds read vulnerability in the MONTH_TO_STRING function. A local, unprivileged attacker can exploit this to read limited internal PLC memory, potentially causing information disclosure or denial of service through application crash. The vulnerability stems from insufficient input validation, specifically allowing negative values to trigger the out-of-bounds access. Attack vector is local (AV:L) with low attack complexity (AC:L) and no privileges required (PR:N).

Defensive priority

medium

Recommended defensive actions

  • Update OSCAT Basic Library to version 3.3.5.0
  • Adjust the library version in CODESYS Library Manager to 3.3.5.0
  • Perform download or online change to update the PLC application
  • Rebuild and download the boot application to ensure persistence
  • If unable to update, validate all input values before passing to affected functions and block negative values as MONTH_TO_STRING parameters
  • Review CERT@VDE advisory VDE-2024-046 for additional technical details

Evidence notes

Vulnerability details and remediation guidance are derived from CISA ICS Advisory ICSA-24-326-02, which references CERT@VDE advisory VDE-2024-046. The advisory confirms the out-of-bounds read vulnerability in the OSCAT Basic Library's MONTH_TO_STRING function and provides specific update and mitigation instructions.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-6876 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-6876

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-6876 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-6876

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-326-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.