PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-33602 Siemens CVE debrief

CVE-2024-33602 is a local memory-corruption flaw in glibc’s nscd netgroup cache. In Siemens advisory ICSA-25-162-05, the issue is mapped to several SIMATIC S7-1500 CPU 1518/1518F MFP variants and a SIPLUS variant, with no fix available at the time of the advisory. The main defensive takeaway is to reduce who can access the affected device’s additional GNU/Linux subsystem and keep execution limited to trusted software and personnel.

Vendor
Siemens
Product
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
CVSS
MEDIUM 4
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-10
Original CVE updated
2026-05-14
Advisory published
2025-06-10
Advisory updated
2026-05-14

Who should care

Siemens SIMATIC S7-1500 operators, OT administrators, and engineers responsible for the affected CPU 1518 MFP / 1518F MFP models, especially environments that use the additional GNU/Linux subsystem or its interactive shell.

Technical summary

The advisory says nscd’s netgroup cache assumes NSS callbacks store all strings in the provided buffer. If a callback keeps strings elsewhere, nscd can corrupt memory while handling the cache. The source notes the flaw was introduced in glibc 2.15 when the cache was added to nscd, and that it is only present in the nscd binary. Siemens ties this to five affected product identifiers and lists no available fix.

Defensive priority

Medium. The supplied CVSS vector is AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L, which points to local access and limited impact, but the affected Siemens products have no fix in the advisory and rely on compensating controls.

Recommended defensive actions

  • Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.
  • Only build and run applications from trusted sources on affected devices.
  • Treat the listed SIMATIC S7-1500 CPU models as affected until Siemens provides a corrective update or revised guidance.
  • Track Siemens ProductCERT and CISA advisory updates for changes to remediation status.
  • Use compensating controls and maintenance planning to reduce exposure in OT environments that rely on the affected subsystem.

Evidence notes

Source evidence comes from Siemens ProductCERT advisory SSA-082556 as republished in CISA CSAF advisory ICSA-25-162-05. The source item lists the affected SIMATIC S7-1500 CPU product names, the nscd/netgroup cache memory-corruption description, the CVSS 3.1 vector, and a remediation entry stating that no fix is currently available. PublishedAt is 2025-06-10 and ModifiedAt is 2026-05-14; those dates are used here for advisory timing context only.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-33602 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-33602

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-33602 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-33602

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.