PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-27983 NodeJS CVE debrief

CVE-2024-27983 is a high-severity denial-of-service vulnerability in Node.js affecting Siemens SINEC INS. The vulnerability stems from an assertion failure in `node::http2::Http2Session::~Http2Session()` that can be triggered by sending a small amount of HTTP/2 frame packets. An unauthenticated remote attacker can exploit this to crash the HTTP/2 server. The vulnerability was published on November 12, 2024, and carries a CVSS 3.1 score of 7.5 (HIGH). Siemens has released a vendor fix in SINEC INS V1.0 SP2 Update 3 or later. This vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog.

Vendor
NodeJS
Product
SINEC INS
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-12
Original CVE updated
2024-11-12
Advisory published
2024-11-12
Advisory updated
2024-11-12

Who should care

Organizations operating Siemens SINEC INS for industrial network infrastructure management, particularly those exposing HTTP/2 services to untrusted networks. Critical infrastructure operators and manufacturing environments relying on SINEC INS for network device management should prioritize patching due to the unauthenticated remote exploitability and high availability impact.

Technical summary

The vulnerability exists in the HTTP/2 session destructor (`node::http2::Http2Session::~Http2Session()`) where an assertion failure can be triggered by malformed or minimal HTTP/2 frame traffic. The attack requires no authentication and can be executed remotely over the network with low complexity. Successful exploitation results in complete loss of availability for the HTTP/2 server component. The underlying issue is in Node.js, which is bundled within Siemens SINEC INS industrial network management software.

Defensive priority

HIGH

Recommended defensive actions

  • Apply Siemens vendor fix: Update SINEC INS to V1.0 SP2 Update 3 or later version
  • Review and restrict network access to HTTP/2 services where patching is not immediately feasible
  • Monitor HTTP/2 traffic for anomalous small frame packet patterns that may indicate exploitation attempts
  • Implement network segmentation for industrial control systems per CISA ICS recommended practices
  • Establish incident response procedures for HTTP/2 service availability disruptions

Evidence notes

Vulnerability description and vendor attribution sourced from CISA CSAF advisory ICSA-24-319-08. CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H confirms network-accessible, unauthenticated attack vector with high availability impact. Remediation guidance sourced from Siemens CSAF remediation entry.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-27983 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-27983

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-27983 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-27983

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-08.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-915275.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-915275.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-08

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.