PatchSiren cyber security CVE debrief
CVE-2024-30045 Siemens CVE debrief
A remote code execution vulnerability in .NET and Visual Studio affects Siemens INTRALOG WMS, published 2024-08-13. The vulnerability could allow arbitrary code execution on INTRALOG WMS application servers. Exploitation requires the attacker to be located within the controlled network of the INTRALOG WMS deployment, limiting the attack surface to insider threats or compromised network segments rather than internet-facing exposure. Siemens has released version 4 or later as a remediation. The CVSS 3.1 score of 5.5 (Medium) reflects the adjacent network attack vector and user interaction requirements.
- Vendor
- Siemens
- Product
- INTRALOG WMS
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-08-13
- Original CVE updated
- 2024-08-13
- Advisory published
- 2024-08-13
- Advisory updated
- 2024-08-13
Who should care
Organizations operating Siemens INTRALOG WMS warehouse management systems, particularly those with network segments accessible to multiple users or integrated with broader enterprise IT environments. Security teams responsible for OT/ICS environments and supply chain logistics infrastructure should prioritize this update.
Technical summary
CVE-2024-30045 is a remote code execution vulnerability in .NET and Visual Studio that affects Siemens INTRALOG WMS warehouse management system. The vulnerability allows potential execution of arbitrary code on INTRALOG WMS application servers. Exploitation is constrained by a network precondition: the attacker must be located within the controlled network of the INTRALOG WMS deployment (CVSS:3.1/AV:A). The CVSS 3.1 vector CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L yields a base score of 5.5 (Medium). Siemens has remediated this in version 4 and later. The vulnerability was disclosed on 2024-08-13 through coordinated disclosure between Microsoft (for the underlying .NET/Visual Studio component) and Siemens (for the affected product integration).
Defensive priority
medium
Recommended defensive actions
- Update Siemens INTRALOG WMS to version 4 or later per vendor guidance
- Restrict network access to INTRALOG WMS application servers to authorized personnel only
- Monitor for anomalous activity on INTRALOG WMS servers from internal network segments
- Apply defense-in-depth controls for industrial control systems per CISA guidance
- Review Microsoft security guidance for CVE-2024-30045 for additional .NET/Visual Studio mitigations
Evidence notes
CVE published 2024-08-13. CISA CSAF advisory ICSA-24-228-02 confirms Siemens INTRALOG WMS as affected product. Vendor fix available: update to V4 or later. Attack vector requires adjacent network access per CVSS:3.1/AV:A.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-30045 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-30045
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-30045 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-30045
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-228-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-417547.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-417547.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-228-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.