PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-32060 Siemens CVE debrief

A high-severity out-of-bounds read vulnerability in Siemens Simcenter Femap allows code execution when parsing malicious IGS files. The flaw, reported via the Zero Day Initiative (ZDI-CAN-21565), stems from reading past the end of an allocated structure during IGS file parsing. With a CVSS 3.1 score of 7.8, this vulnerability requires local access and user interaction but grants high impact across confidentiality, integrity, and availability. CISA published advisory ICSA-24-193-04 on July 9, 2024, coordinating disclosure with Siemens. The vendor has released version V2406 as a definitive fix.

Vendor
Siemens
Product
Simcenter Femap
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-05-14
Original CVE updated
2024-05-14
Advisory published
2024-05-14
Advisory updated
2024-05-14

Who should care

Engineering organizations using Siemens Simcenter Femap for finite element analysis and CAD preprocessing; security teams in manufacturing, aerospace, automotive, and energy sectors; ICS/OT security practitioners managing engineering workstations; asset owners with Simcenter Femap deployments in design and simulation workflows.

Technical summary

CVE-2024-32060 is an out-of-bounds read vulnerability in Siemens Simcenter Femap that occurs when parsing specially crafted IGS (Initial Graphics Exchange Specification) files. The vulnerability allows an attacker to read memory beyond allocated structure boundaries, potentially leading to code execution in the context of the current process. The flaw was reported through the Zero Day Initiative (ZDI-CAN-21565) and affects versions prior to V2406. The attack vector requires local access and user interaction—specifically, opening a malicious IGS file. Successful exploitation grants high impact on confidentiality, integrity, and availability. Siemens has released version V2406 as the definitive remediation. CISA's advisory ICSA-24-193-04 provides coordinated disclosure and mitigation guidance for industrial control systems environments.

Defensive priority

HIGH

Recommended defensive actions

  • Update Simcenter Femap to version V2406 or later to remediate this vulnerability
  • Apply vendor security updates from Siemens ProductCERT SSA-064222
  • Restrict opening of untrusted IGS files in Simcenter Femap as a temporary mitigation
  • Implement defense-in-depth controls for industrial control systems environments per CISA guidance
  • Monitor for anomalous IGS file handling in engineering workstations running Simcenter Femap

Evidence notes

The vulnerability was reported through the Zero Day Initiative (ZDI-CAN-21565). CISA's CSAF-based advisory confirms the out-of-bounds read occurs during parsing of specially crafted IGS files in Simcenter Femap. Siemens ProductCERT SSA-064222 provides the authoritative vendor fix in version V2406.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-32060 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-32060

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-32060 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-32060

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-193-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-064222.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-064222.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-064222.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-064222.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-193-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.