PatchSiren cyber security CVE debrief
CVE-2023-24936 Siemens CVE debrief
CVE-2023-24936 is a high-severity elevation of privilege vulnerability affecting .NET, .NET Framework, and Visual Studio. The vulnerability was published on June 11, 2024, with a CVSS 3.1 score of 7.5 (HIGH). Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0) is identified as an affected product in this advisory. The vulnerability requires user interaction and high attack complexity, with network attack vector and no privileges required for exploitation. Successful exploitation could result in high impact to confidentiality, integrity, and availability. Siemens has released a vendor fix recommending update to version 1.1 or later.
- Vendor
- Siemens
- Product
- ST7 ScadaConnect (6NH7997-5DA10-0AA0)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-11
- Original CVE updated
- 2024-06-11
- Advisory published
- 2024-06-11
- Advisory updated
- 2024-06-11
Who should care
Organizations operating Siemens ST7 ScadaConnect systems in OT/ICS environments, security teams responsible for .NET and Visual Studio deployments, and infrastructure administrators managing industrial control systems should prioritize this vulnerability for remediation.
Technical summary
CVE-2023-24936 is an elevation of privilege vulnerability in .NET, .NET Framework, and Visual Studio with CVSS 3.1 score 7.5 (HIGH). The vulnerability affects Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0). Attack vector is network-based with high complexity and requires user interaction. Successful exploitation grants high impact to confidentiality, integrity, and availability. Siemens has released version 1.1 as a remediation. The vulnerability was disclosed June 11, 2024 via CISA advisory ICSA-24-165-04 and Siemens SSA-341067.
Defensive priority
HIGH
Recommended defensive actions
- Apply the vendor-provided update to version 1.1 or later for Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0)
- Review and implement CISA ICS recommended practices for defense-in-depth strategies
- Monitor for additional vendor guidance from Siemens ProductCERT
- Assess environment for other .NET/.NET Framework/Visual Studio components that may require patching
- Implement network segmentation for OT/ICS environments per CISA guidance
Evidence notes
The vulnerability description is sourced from CISA CSAF advisory ICSA-24-165-04, which references Siemens security advisory SSA-341067. The affected product is ST7 ScadaConnect (6NH7997-5DA10-0AA0). CVSS vector indicates network attack vector, high attack complexity, user interaction required, and high impacts across confidentiality, integrity, and availability.
Official resources
-
CVE-2023-24936 CVE record
CVE.org
-
CVE-2023-24936 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
This vulnerability was disclosed through coordinated disclosure. CISA published advisory ICSA-24-165-04 on June 11, 2024, referencing Siemens security advisory SSA-341067. The vulnerability affects industrial control system components andOT