PatchSiren cyber security CVE debrief
CVE-2024-27983 NodeJS CVE debrief
CVE-2024-27983 is a high-severity denial-of-service vulnerability in Node.js affecting Siemens SINEC INS. The vulnerability stems from an assertion failure in `node::http2::Http2Session::~Http2Session()` that can be triggered by sending a small amount of HTTP/2 frame packets. An unauthenticated remote attacker can exploit this to crash the HTTP/2 server. The vulnerability was published on November 12, 2024, and carries a CVSS 3.1 score of 7.5 (HIGH). Siemens has released a vendor fix in SINEC INS V1.0 SP2 Update 3 or later. This vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog.
- Vendor
- NodeJS
- Product
- SINEC INS
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-12
- Original CVE updated
- 2024-11-12
- Advisory published
- 2024-11-12
- Advisory updated
- 2024-11-12
Who should care
Organizations operating Siemens SINEC INS for industrial network infrastructure management, particularly those exposing HTTP/2 services to untrusted networks. Critical infrastructure operators and manufacturing environments relying on SINEC INS for network device management should prioritize patching due to the unauthenticated remote exploitability and high availability impact.
Technical summary
The vulnerability exists in the HTTP/2 session destructor (`node::http2::Http2Session::~Http2Session()`) where an assertion failure can be triggered by malformed or minimal HTTP/2 frame traffic. The attack requires no authentication and can be executed remotely over the network with low complexity. Successful exploitation results in complete loss of availability for the HTTP/2 server component. The underlying issue is in Node.js, which is bundled within Siemens SINEC INS industrial network management software.
Defensive priority
HIGH
Recommended defensive actions
- Apply Siemens vendor fix: Update SINEC INS to V1.0 SP2 Update 3 or later version
- Review and restrict network access to HTTP/2 services where patching is not immediately feasible
- Monitor HTTP/2 traffic for anomalous small frame packet patterns that may indicate exploitation attempts
- Implement network segmentation for industrial control systems per CISA ICS recommended practices
- Establish incident response procedures for HTTP/2 service availability disruptions
Evidence notes
Vulnerability description and vendor attribution sourced from CISA CSAF advisory ICSA-24-319-08. CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H confirms network-accessible, unauthenticated attack vector with high availability impact. Remediation guidance sourced from Siemens CSAF remediation entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-27983 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-27983
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-27983 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-27983
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-08.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-915275.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-915275.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-08
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.