PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-29857 Siemens CVE debrief

CVE-2024-29857 is a high-severity availability issue affecting Siemens SIDIS Prime versions before 4.0.800. According to the CISA/Siemens advisory chain, importing an EC certificate with crafted F2m parameters can drive excessive CPU consumption while curve parameters are evaluated. The vendor remediation is to update to V4.0.800 or later.

Vendor
Siemens
Product
SIDIS Prime
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-10
Original CVE updated
2026-03-12
Advisory published
2026-03-10
Advisory updated
2026-03-12

Who should care

Operators and administrators responsible for Siemens SIDIS Prime deployments, especially systems that import or process EC certificates. Security teams should also review any environments where SIDIS Prime is exposed to untrusted certificate input.

Technical summary

The advisory describes a CPU-consumption problem in certificate handling tied to evaluation of elliptic-curve parameters. Specifically, crafted EC certificates with F2m parameters can trigger expensive processing in ECCurve.java and ECCurve.cs, resulting in excessive CPU use and an availability impact. The advisory’s CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, reflecting a network-reachable, low-complexity denial-of-service condition.

Defensive priority

High. The issue is rated CVSS 7.5 and can materially affect availability by consuming CPU during certificate import or validation. Systems that rely on SIDIS Prime should be checked promptly and upgraded.

Recommended defensive actions

  • Update Siemens SIDIS Prime to V4.0.800 or later as directed in the advisory.
  • Inventory where SIDIS Prime is deployed and determine whether EC certificate import is enabled or reachable.
  • Prioritize remediation on systems that process untrusted or externally supplied certificates.
  • Monitor affected systems for abnormal CPU spikes during certificate handling and validate that the fixed version is deployed.
  • Use CISA and vendor recommended practices to reduce exposure while patching and verify the advisory guidance before making operational changes.

Evidence notes

The source corpus ties CVE-2024-29857 to Siemens SIDIS Prime in CISA advisory ICSA-26-071-03, republished from Siemens ProductCERT SSA-485750. The advisory was published on 2026-03-10 and republished on 2026-03-12. The supplied remediation states: update to V4.0.800 or later. The provided CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-29857 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-29857

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-29857 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-29857

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-485750.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-485750.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-071-03.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.