PatchSiren cyber security CVE debrief
CVE-2023-24936 Siemens CVE debrief
CVE-2023-24936 is a high-severity elevation of privilege vulnerability affecting .NET, .NET Framework, and Visual Studio. The vulnerability was published on June 11, 2024, with a CVSS 3.1 score of 7.5 (HIGH). Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0) is identified as an affected product in this advisory. The vulnerability requires user interaction and high attack complexity, with network attack vector and no privileges required for exploitation. Successful exploitation could result in high impact to confidentiality, integrity, and availability. Siemens has released a vendor fix recommending update to version 1.1 or later.
- Vendor
- Siemens
- Product
- ST7 ScadaConnect (6NH7997-5DA10-0AA0)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-11-14
- Original CVE updated
- 2023-11-14
- Advisory published
- 2023-11-14
- Advisory updated
- 2023-11-14
Who should care
Organizations operating Siemens ST7 ScadaConnect systems in OT/ICS environments, security teams responsible for .NET and Visual Studio deployments, and infrastructure administrators managing industrial control systems should prioritize this vulnerability for remediation.
Technical summary
CVE-2023-24936 is an elevation of privilege vulnerability in .NET, .NET Framework, and Visual Studio with CVSS 3.1 score 7.5 (HIGH). The vulnerability affects Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0). Attack vector is network-based with high complexity and requires user interaction. Successful exploitation grants high impact to confidentiality, integrity, and availability. Siemens has released version 1.1 as a remediation. The vulnerability was disclosed June 11, 2024 via CISA advisory ICSA-24-165-04 and Siemens SSA-341067.
Defensive priority
HIGH
Recommended defensive actions
- Apply the vendor-provided update to version 1.1 or later for Siemens ST7 ScadaConnect (6NH7997-5DA10-0AA0)
- Review and implement CISA ICS recommended practices for defense-in-depth strategies
- Monitor for additional vendor guidance from Siemens ProductCERT
- Assess environment for other .NET/.NET Framework/Visual Studio components that may require patching
- Implement network segmentation for OT/ICS environments per CISA guidance
Evidence notes
The vulnerability description is sourced from CISA CSAF advisory ICSA-24-165-04, which references Siemens security advisory SSA-341067. The affected product is ST7 ScadaConnect (6NH7997-5DA10-0AA0). CVSS vector indicates network attack vector, high attack complexity, user interaction required, and high impacts across confidentiality, integrity, and availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-24936 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-24936
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-24936 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-24936
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-341067.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-341067.html
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/pdf/ssa-341067.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/txt/ssa-341067.txt
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.