PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-24936 Siemens CVE debrief

CVE-2023-24936 is a high-severity elevation of privilege vulnerability affecting .NET, .NET Framework, and Visual Studio. The vulnerability was published on June 11, 2024, with a CVSS 3.1 score of 7.5 (HIGH). Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0) is identified as an affected product in this advisory. The vulnerability requires user interaction and high attack complexity, with network attack vector and no privileges required for exploitation. Successful exploitation could result in high impact to confidentiality, integrity, and availability. Siemens has released a vendor fix recommending update to version 1.1 or later.

Vendor
Siemens
Product
ST7 ScadaConnect (6NH7997-5DA10-0AA0)
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2023-11-14
Original CVE updated
2023-11-14
Advisory published
2023-11-14
Advisory updated
2023-11-14

Who should care

Organizations operating Siemens ST7 ScadaConnect systems in OT/ICS environments, security teams responsible for .NET and Visual Studio deployments, and infrastructure administrators managing industrial control systems should prioritize this vulnerability for remediation.

Technical summary

CVE-2023-24936 is an elevation of privilege vulnerability in .NET, .NET Framework, and Visual Studio with CVSS 3.1 score 7.5 (HIGH). The vulnerability affects Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0). Attack vector is network-based with high complexity and requires user interaction. Successful exploitation grants high impact to confidentiality, integrity, and availability. Siemens has released version 1.1 as a remediation. The vulnerability was disclosed June 11, 2024 via CISA advisory ICSA-24-165-04 and Siemens SSA-341067.

Defensive priority

HIGH

Recommended defensive actions

  • Apply the vendor-provided update to version 1.1 or later for Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0)
  • Review and implement CISA ICS recommended practices for defense-in-depth strategies
  • Monitor for additional vendor guidance from Siemens ProductCERT
  • Assess environment for other .NET/.NET Framework/Visual Studio components that may require patching
  • Implement network segmentation for OT/ICS environments per CISA guidance

Evidence notes

The vulnerability description is sourced from CISA CSAF advisory ICSA-24-165-04, which references Siemens security advisory SSA-341067. The affected product is ST7 ScadaConnect (6NH7997-5DA10-0AA0). CVSS vector indicates network attack vector, high attack complexity, user interaction required, and high impacts across confidentiality, integrity, and availability.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-24936 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-24936

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-24936 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-24936

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-341067.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-341067.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-341067.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-341067.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.