PatchSiren cyber security CVE debrief
CVE-2024-2004 curl CVE debrief
CVE-2024-2004 is a protocol selection logic flaw in curl that affects Siemens SINEC NMS. When the `--proto` option is used to disable all protocols without subsequently enabling any, the default protocol set incorrectly remains in the allowed set due to an error in the removal logic. This could allow a request to proceed using a protocol that was explicitly disabled, such as plaintext HTTP. The vulnerability only manifests when the entire set of available protocols is disabled—a configuration with no practical use case—making real-world exploitation unlikely. The curl security team assessed this as low severity. Siemens has addressed this in SINEC NMS by releasing V3.0 SP1 or later.
- Vendor
- curl
- Product
- SINEMA Remote Connect Client
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-12-12
- Original CVE updated
- 2025-08-12
- Advisory published
- 2023-12-12
- Advisory updated
- 2025-08-12
Who should care
Organizations operating Siemens SINEC NMS in industrial control system environments should apply the vendor update. Security teams reviewing curl configurations in embedded or OT products should verify protocol restriction implementations. The low practical impact limits broader concern, but defense-in-depth principles support patching.
Technical summary
The vulnerability exists in curl's protocol selection logic. When using `--proto -all,-http` to disable all protocols including HTTP, the intended behavior is to block all protocol access. However, due to a logic error in protocol removal, the default protocol set remains allowed. This means a subsequent request to an HTTP URL would still proceed despite explicit disabling. The flaw requires a specific, non-functional configuration (disabling all protocols without enabling any), which limits practical exploitability. The fix ensures proper protocol set management when all protocols are disabled.
Defensive priority
low
Recommended defensive actions
- Update Siemens SINEC NMS to V3.0 SP1 or later version to address the embedded curl vulnerability
- Review application configurations that use curl's --proto option to ensure protocol restrictions are properly implemented
- Monitor vendor security advisories for Siemens SINEC NMS for additional guidance
Evidence notes
The vulnerability description is derived from CISA ICS Advisory ICSA-24-319-04, which references Siemens Security Advisory SSA-331112. The flaw is specific to curl's protocol selection parameter handling and does not represent a protocol implementation vulnerability. The affected product is Siemens SINEC NMS, which incorporates the vulnerable curl component.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-2004 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-2004
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-2004 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-2004
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-256-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-417159.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-417159.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.