PatchSiren cyber security CVE debrief
CVE-2024-0232 Siemens CVE debrief
CVE-2024-0232 is a medium-severity issue affecting Siemens SIDIS Prime. The advisory describes a heap use-after-free in SQLite's jsonParseAddNodeArray() function that can be triggered through specially crafted malicious input, with the likely outcome being a crash and denial of service. Siemens' remediation is to update SIDIS Prime to V4.0.700 or later.
- Vendor
- Siemens
- Product
- SIDIS Prime
- CVSS
- MEDIUM 4.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-06-13
- Original CVE updated
- 2024-04-09
- Advisory published
- 2023-06-13
- Advisory updated
- 2024-04-09
Who should care
Siemens SIDIS Prime operators, OT administrators, and security teams responsible for maintaining the application should prioritize this advisory, especially where untrusted or user-supplied JSON data may be processed.
Technical summary
The source advisory attributes the flaw to a heap use-after-free in sqlite3.c, specifically in jsonParseAddNodeArray(). The published CVSS vector (AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H) indicates a locally reachable issue that requires user interaction and can disrupt availability. The affected product listed in the CSAF advisory is Siemens SIDIS Prime, and the vendor remediation is to update to V4.0.700 or later.
Defensive priority
Medium. The issue is limited to availability impact, but OT-facing software should still be patched promptly because crashes in operational tooling can interrupt workflows or monitoring.
Recommended defensive actions
- Update Siemens SIDIS Prime to V4.0.700 or later as directed by the vendor advisory.
- Validate whether SIDIS Prime processes externally influenced or user-provided JSON input and restrict that input path where possible.
- Apply compensating controls to limit local access and reduce exposure to untrusted user interaction.
- Review system stability monitoring and logging for unexpected crashes or restarts until remediation is complete.
- Track the Siemens and CISA advisories for any further revisions or guidance.
Evidence notes
All substantive claims in this debrief come from the supplied CISA CSAF source item for ICSA-25-100-02 and its referenced Siemens advisory materials. The source item states the affected product is Siemens SIDIS Prime, describes a heap use-after-free in SQLite's jsonParseAddNodeArray() function, and gives the remediation as V4.0.700 or later. The source revision history shows the advisory was published on 2025-04-08 and later revised on 2025-05-06 for typo fixes only.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-0232 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-0232
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-0232 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-0232
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-100-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-277137.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-277137.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.