PatchSiren cyber security CVE debrief
CVE-2024-29857 Siemens CVE debrief
CVE-2024-29857 is a high-severity availability issue affecting Siemens SIDIS Prime versions before 4.0.800. According to the CISA/Siemens advisory chain, importing an EC certificate with crafted F2m parameters can drive excessive CPU consumption while curve parameters are evaluated. The vendor remediation is to update to V4.0.800 or later.
- Vendor
- Siemens
- Product
- SIDIS Prime
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-10
- Original CVE updated
- 2026-03-12
- Advisory published
- 2026-03-10
- Advisory updated
- 2026-03-12
Who should care
Operators and administrators responsible for Siemens SIDIS Prime deployments, especially systems that import or process EC certificates. Security teams should also review any environments where SIDIS Prime is exposed to untrusted certificate input.
Technical summary
The advisory describes a CPU-consumption problem in certificate handling tied to evaluation of elliptic-curve parameters. Specifically, crafted EC certificates with F2m parameters can trigger expensive processing in ECCurve.java and ECCurve.cs, resulting in excessive CPU use and an availability impact. The advisory’s CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, reflecting a network-reachable, low-complexity denial-of-service condition.
Defensive priority
High. The issue is rated CVSS 7.5 and can materially affect availability by consuming CPU during certificate import or validation. Systems that rely on SIDIS Prime should be checked promptly and upgraded.
Recommended defensive actions
- Update Siemens SIDIS Prime to V4.0.800 or later as directed in the advisory.
- Inventory where SIDIS Prime is deployed and determine whether EC certificate import is enabled or reachable.
- Prioritize remediation on systems that process untrusted or externally supplied certificates.
- Monitor affected systems for abnormal CPU spikes during certificate handling and validate that the fixed version is deployed.
- Use CISA and vendor recommended practices to reduce exposure while patching and verify the advisory guidance before making operational changes.
Evidence notes
The source corpus ties CVE-2024-29857 to Siemens SIDIS Prime in CISA advisory ICSA-26-071-03, republished from Siemens ProductCERT SSA-485750. The advisory was published on 2026-03-10 and republished on 2026-03-12. The supplied remediation states: update to V4.0.800 or later. The provided CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-29857 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-29857
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-29857 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-29857
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-485750.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-485750.html
Reference
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-071-03.json
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.