PatchSiren cyber security CVE debrief
CVE-2023-34050 Siemens CVE debrief
CVE-2023-34050 is a deserialization vulnerability in Spring AMQP affecting versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9. The vulnerability stems from insecure default configuration: when no allowed list patterns are specified for deserializable class names, all classes can be deserialized by default. This exposes applications to potential remote code execution when using SimpleMessageConverter or SerializerMessageConverter with untrusted message sources that can write to the RabbitMQ broker. The vulnerability was published on August 13, 2024, with a CVSS 3.1 score of 5.0 (MEDIUM). Siemens SINEC NMS is identified as an affected product, with remediation available through update to version 3.0 or later.
- Vendor
- Siemens
- Product
- SINEC NMS
- CVSS
- MEDIUM 5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-08-13
- Original CVE updated
- 2024-08-13
- Advisory published
- 2024-08-13
- Advisory updated
- 2024-08-13
Who should care
Organizations running Siemens SINEC NMS with affected Spring AMQP versions, OT/ICS security teams managing RabbitMQ message brokers, and developers implementing Spring AMQP message converters without allowed list restrictions.
Technical summary
The vulnerability exists in Spring AMQP's message conversion components. When SimpleMessageConverter or SerializerMessageConverter processes messages without configured allowed list patterns, arbitrary Java classes can be deserialized from message payloads. This creates a deserialization attack surface when untrusted actors can publish messages to the RabbitMQ broker. The attack requires network access to the broker (AV:N), high attack complexity (AC:H), and high privileges (PR:H), with potential for high availability impact (A:H) and low integrity impact (I:L).
Defensive priority
medium
Recommended defensive actions
- Update Siemens SINEC NMS to version 3.0 or later per vendor guidance
- Configure allowed list patterns for deserializable class names in Spring AMQP if not using vendor fix
- Review RabbitMQ broker access controls to restrict untrusted message originators
- Audit applications using SimpleMessageConverter or SerializerMessageConverter for deserialization configurations
- Apply defense-in-depth controls for industrial control systems per CISA recommended practices
Evidence notes
CVE description confirms Spring AMQP versions 1.0.0-2.4.16 and 3.0.0-3.0.9 affected. CISA CSAF advisory ICSA-24-228-06 identifies Siemens SINEC NMS as impacted product. CVSS vector from source: AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H/E:P/RL:O/RC:C.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-34050 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-34050
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-34050 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-34050
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-228-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-784301.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-784301.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-228-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.