PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-30045 Siemens CVE debrief

A remote code execution vulnerability in .NET and Visual Studio affects Siemens INTRALOG WMS, published 2024-08-13. The vulnerability could allow arbitrary code execution on INTRALOG WMS application servers. Exploitation requires the attacker to be located within the controlled network of the INTRALOG WMS deployment, limiting the attack surface to insider threats or compromised network segments rather than internet-facing exposure. Siemens has released version 4 or later as a remediation. The CVSS 3.1 score of 5.5 (Medium) reflects the adjacent network attack vector and user interaction requirements.

Vendor
Siemens
Product
INTRALOG WMS
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-08-13
Original CVE updated
2024-08-13
Advisory published
2024-08-13
Advisory updated
2024-08-13

Who should care

Organizations operating Siemens INTRALOG WMS warehouse management systems, particularly those with network segments accessible to multiple users or integrated with broader enterprise IT environments. Security teams responsible for OT/ICS environments and supply chain logistics infrastructure should prioritize this update.

Technical summary

CVE-2024-30045 is a remote code execution vulnerability in .NET and Visual Studio that affects Siemens INTRALOG WMS warehouse management system. The vulnerability allows potential execution of arbitrary code on INTRALOG WMS application servers. Exploitation is constrained by a network precondition: the attacker must be located within the controlled network of the INTRALOG WMS deployment (CVSS:3.1/AV:A). The CVSS 3.1 vector CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L yields a base score of 5.5 (Medium). Siemens has remediated this in version 4 and later. The vulnerability was disclosed on 2024-08-13 through coordinated disclosure between Microsoft (for the underlying .NET/Visual Studio component) and Siemens (for the affected product integration).

Defensive priority

medium

Recommended defensive actions

  • Update Siemens INTRALOG WMS to version 4 or later per vendor guidance
  • Restrict network access to INTRALOG WMS application servers to authorized personnel only
  • Monitor for anomalous activity on INTRALOG WMS servers from internal network segments
  • Apply defense-in-depth controls for industrial control systems per CISA guidance
  • Review Microsoft security guidance for CVE-2024-30045 for additional .NET/Visual Studio mitigations

Evidence notes

CVE published 2024-08-13. CISA CSAF advisory ICSA-24-228-02 confirms Siemens INTRALOG WMS as affected product. Vendor fix available: update to V4 or later. Attack vector requires adjacent network access per CVSS:3.1/AV:A.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-30045 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-30045

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-30045 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-30045

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-228-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-417547.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-417547.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-228-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.