PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-0232 Siemens CVE debrief

CVE-2024-0232 is a medium-severity issue affecting Siemens SIDIS Prime. The advisory describes a heap use-after-free in SQLite's jsonParseAddNodeArray() function that can be triggered through specially crafted malicious input, with the likely outcome being a crash and denial of service. Siemens' remediation is to update SIDIS Prime to V4.0.700 or later.

Vendor
Siemens
Product
SIDIS Prime
CVSS
MEDIUM 4.7
CISA KEV
Not listed in stored evidence
Original CVE published
2023-06-13
Original CVE updated
2024-04-09
Advisory published
2023-06-13
Advisory updated
2024-04-09

Who should care

Siemens SIDIS Prime operators, OT administrators, and security teams responsible for maintaining the application should prioritize this advisory, especially where untrusted or user-supplied JSON data may be processed.

Technical summary

The source advisory attributes the flaw to a heap use-after-free in sqlite3.c, specifically in jsonParseAddNodeArray(). The published CVSS vector (AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H) indicates a locally reachable issue that requires user interaction and can disrupt availability. The affected product listed in the CSAF advisory is Siemens SIDIS Prime, and the vendor remediation is to update to V4.0.700 or later.

Defensive priority

Medium. The issue is limited to availability impact, but OT-facing software should still be patched promptly because crashes in operational tooling can interrupt workflows or monitoring.

Recommended defensive actions

  • Update Siemens SIDIS Prime to V4.0.700 or later as directed by the vendor advisory.
  • Validate whether SIDIS Prime processes externally influenced or user-provided JSON input and restrict that input path where possible.
  • Apply compensating controls to limit local access and reduce exposure to untrusted user interaction.
  • Review system stability monitoring and logging for unexpected crashes or restarts until remediation is complete.
  • Track the Siemens and CISA advisories for any further revisions or guidance.

Evidence notes

All substantive claims in this debrief come from the supplied CISA CSAF source item for ICSA-25-100-02 and its referenced Siemens advisory materials. The source item states the affected product is Siemens SIDIS Prime, describes a heap use-after-free in SQLite's jsonParseAddNodeArray() function, and gives the remediation as V4.0.700 or later. The source revision history shows the advisory was published on 2025-04-08 and later revised on 2025-05-06 for typo fixes only.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-0232 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-0232

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-0232 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-0232

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-100-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-277137.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-277137.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.