PatchSiren cyber security CVE debrief
CVE-2024-31484 Siemens CVE debrief
CVE-2024-31484 is a HIGH severity vulnerability (CVSS 7.8) affecting Siemens SICAM RTU components, published on June 11, 2024. The vulnerability stems from improper null termination during parsing of a specific HTTP header, which can lead to code execution in the context of the current process or cause denial of service conditions. The affected products include CPCX26 Central Processing/Communication, ETA4 Ethernet Interface IEC60870-5-104, ETA5 Ethernet Interface IEC61850 Ed.2, and PCCX26 Ax 1703 PE Communication Element—all components used in industrial control and substation automation environments. Siemens has released firmware updates for all affected products, which are distributed through the SICAM RTUs AK3 Package V06.02. Given the critical infrastructure context of these devices, organizations should prioritize patching and implement network segmentation to limit exposure.
- Vendor
- Siemens
- Product
- CPCX26 Central Processing/Communication
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-05-14
- Original CVE updated
- 2024-06-11
- Advisory published
- 2024-05-14
- Advisory updated
- 2024-06-11
Who should care
Organizations operating Siemens SICAM RTU systems in electrical substations, power generation facilities, and industrial automation environments. Critical infrastructure operators subject to NERC CIP or similar regulatory frameworks should prioritize assessment and remediation.
Technical summary
The vulnerability exists in the HTTP header parsing implementation of affected Siemens SICAM RTU devices. Improper null termination during parsing of a specific HTTP header can result in memory corruption, enabling an attacker to achieve code execution within the current process context or trigger a denial of service condition. The attack vector requires local access with user interaction (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). This affects four product variants used in power grid and industrial automation: CPCX26 Central Processing/Communication, ETA4 Ethernet Interface (IEC60870-5-104), ETA5 Ethernet Interface (IEC61850 Ed.2), and PCCX26 Ax 1703 PE Communication Element.
Defensive priority
HIGH
Recommended defensive actions
- Apply vendor-provided firmware updates: CPCX26 to V06.02 or later, PCCX26 to V06.05 or later, ETA4 to V10.46 or later, and ETA5 to V03.27 or later, available through SICAM RTUs AK3 Package V06.02
- Restrict network access to affected devices using firewall rules and network segmentation
- Monitor for anomalous HTTP traffic targeting SICAM RTU devices
- Implement defense-in-depth strategies for industrial control systems per CISA guidance
- Review and update incident response procedures for industrial control system compromises
Evidence notes
Vulnerability details and remediation guidance sourced from CISA ICS advisory ICSA-24-165-09 and Siemens security advisory SSA-620338. CVSS 3.1 vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-31484 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-31484
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-31484 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-31484
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-620338.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-620338.html
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/pdf/ssa-620338.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/txt/ssa-620338.txt
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.