PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-24936 Siemens CVE debrief

CVE-2023-24936 is a high-severity elevation of privilege vulnerability affecting .NET, .NET Framework, and Visual Studio. The vulnerability was published on June 11, 2024, with a CVSS 3.1 score of 7.5 (HIGH). Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0) is identified as an affected product in this advisory. The vulnerability requires user interaction and high attack complexity, with network attack vector and no privileges required for exploitation. Successful exploitation could result in high impact to confidentiality, integrity, and availability. Siemens has released a vendor fix recommending update to version 1.1 or later.

Vendor
Siemens
Product
ST7 ScadaConnect (6NH7997-5DA10-0AA0)
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-11
Original CVE updated
2024-06-11
Advisory published
2024-06-11
Advisory updated
2024-06-11

Who should care

Organizations operating Siemens ST7 ScadaConnect systems in OT/ICS environments, security teams responsible for .NET and Visual Studio deployments, and infrastructure administrators managing industrial control systems should prioritize this vulnerability for remediation.

Technical summary

CVE-2023-24936 is an elevation of privilege vulnerability in .NET, .NET Framework, and Visual Studio with CVSS 3.1 score 7.5 (HIGH). The vulnerability affects Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0). Attack vector is network-based with high complexity and requires user interaction. Successful exploitation grants high impact to confidentiality, integrity, and availability. Siemens has released version 1.1 as a remediation. The vulnerability was disclosed June 11, 2024 via CISA advisory ICSA-24-165-04 and Siemens SSA-341067.

Defensive priority

HIGH

Recommended defensive actions

  • Apply the vendor-provided update to version 1.1 or later for Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0)
  • Review and implement CISA ICS recommended practices for defense-in-depth strategies
  • Monitor for additional vendor guidance from Siemens ProductCERT
  • Assess environment for other .NET/.NET Framework/Visual Studio components that may require patching
  • Implement network segmentation for OT/ICS environments per CISA guidance

Evidence notes

The vulnerability description is sourced from CISA CSAF advisory ICSA-24-165-04, which references Siemens security advisory SSA-341067. The affected product is ST7 ScadaConnect (6NH7997-5DA10-0AA0). CVSS vector indicates network attack vector, high attack complexity, user interaction required, and high impacts across confidentiality, integrity, and availability.

Official resources

This vulnerability was disclosed through coordinated disclosure. CISA published advisory ICSA-24-165-04 on June 11, 2024, referencing Siemens security advisory SSA-341067. The vulnerability affects industrial control system components andOT