PatchSiren cyber security CVE debrief
CVE-2024-33600 Siemens CVE debrief
CVE-2024-33600 is a medium-severity availability issue mapped by CISA and Siemens to five SIMATIC S7-1500 CPU product variants. The underlying flaw is a null pointer dereference in nscd after a notfound netgroup response if the cache fails to store the result. The source advisory states that no fix is currently available, so defense centers on limiting access to the additional GNU/Linux subsystem and using trusted software only.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Operators and maintainers of the listed Siemens SIMATIC S7-1500 CPU variants, especially environments that use the additional GNU/Linux subsystem or expose its interactive shell to more than a tightly controlled admin group.
Technical summary
The advisory describes a null pointer crash in the Name Service Cache Daemon (nscd) when a not-found netgroup response cannot be added to cache, leading a client request to dereference a null pointer. The issue was introduced in glibc 2.15 when the cache was added to nscd and is stated to exist only in the nscd binary. In the Siemens/CISA advisory, the affected scope is limited to five SIMATIC S7-1500 CPU variants. The published CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L, which aligns with an availability-only crash condition.
Defensive priority
Medium. The CVSS score is 5.3 and the modeled impact is limited to availability, but ICS deployments should still treat it as operationally relevant because a crash in a subsystem component can disrupt plant workflows. Prioritize if the affected CPU family is deployed and the additional GNU/Linux subsystem is in use.
Recommended defensive actions
- Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.
- Only build and run applications from trusted sources on the affected systems.
- Track Siemens ProductCERT and CISA updates for a vendor fix; the advisory states that currently no fix is available.
- Inventory the five listed SIMATIC S7-1500 CPU variants and confirm whether the additional GNU/Linux subsystem is enabled in your deployment.
Evidence notes
The source corpus ties CVE-2024-33600 to Siemens advisory SSA-082556 / CISA ICSA-25-162-05 and lists five affected SIMATIC S7-1500 CPU product names. The advisory description says the flaw is a null pointer dereference in nscd after a notfound netgroup response when caching fails, and it explicitly says the vulnerability is only present in the nscd binary. The remediation section states that no fix is currently available. Timing context: the CVE and source item were published on 2025-06-10 and were last updated in the supplied corpus on 2026-05-14.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-33600 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-33600
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-33600 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-33600
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.