PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-2004 curl CVE debrief

CVE-2024-2004 is a protocol selection logic flaw in curl that affects Siemens SINEC NMS. When the `--proto` option is used to disable all protocols without subsequently enabling any, the default protocol set incorrectly remains in the allowed set due to an error in the removal logic. This could allow a request to proceed using a protocol that was explicitly disabled, such as plaintext HTTP. The vulnerability only manifests when the entire set of available protocols is disabled—a configuration with no practical use case—making real-world exploitation unlikely. The curl security team assessed this as low severity. Siemens has addressed this in SINEC NMS by releasing V3.0 SP1 or later.

Vendor
curl
Product
SINEMA Remote Connect Client
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2023-12-12
Original CVE updated
2025-08-12
Advisory published
2023-12-12
Advisory updated
2025-08-12

Who should care

Organizations operating Siemens SINEC NMS in industrial control system environments should apply the vendor update. Security teams reviewing curl configurations in embedded or OT products should verify protocol restriction implementations. The low practical impact limits broader concern, but defense-in-depth principles support patching.

Technical summary

The vulnerability exists in curl's protocol selection logic. When using `--proto -all,-http` to disable all protocols including HTTP, the intended behavior is to block all protocol access. However, due to a logic error in protocol removal, the default protocol set remains allowed. This means a subsequent request to an HTTP URL would still proceed despite explicit disabling. The flaw requires a specific, non-functional configuration (disabling all protocols without enabling any), which limits practical exploitability. The fix ensures proper protocol set management when all protocols are disabled.

Defensive priority

low

Recommended defensive actions

  • Update Siemens SINEC NMS to V3.0 SP1 or later version to address the embedded curl vulnerability
  • Review application configurations that use curl's --proto option to ensure protocol restrictions are properly implemented
  • Monitor vendor security advisories for Siemens SINEC NMS for additional guidance

Evidence notes

The vulnerability description is derived from CISA ICS Advisory ICSA-24-319-04, which references Siemens Security Advisory SSA-331112. The flaw is specific to curl's protocol selection parameter handling and does not represent a protocol implementation vulnerability. The affected product is Siemens SINEC NMS, which incorporates the vulnerable curl component.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-2004 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-2004

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-2004 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-2004

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-256-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-417159.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-417159.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.