PatchSiren cyber security CVE debrief
CVE-2024-33602 Siemens CVE debrief
CVE-2024-33602 is a local memory-corruption flaw in glibc’s nscd netgroup cache. In Siemens advisory ICSA-25-162-05, the issue is mapped to several SIMATIC S7-1500 CPU 1518/1518F MFP variants and a SIPLUS variant, with no fix available at the time of the advisory. The main defensive takeaway is to reduce who can access the affected device’s additional GNU/Linux subsystem and keep execution limited to trusted software and personnel.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
- CVSS
- MEDIUM 4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Siemens SIMATIC S7-1500 operators, OT administrators, and engineers responsible for the affected CPU 1518 MFP / 1518F MFP models, especially environments that use the additional GNU/Linux subsystem or its interactive shell.
Technical summary
The advisory says nscd’s netgroup cache assumes NSS callbacks store all strings in the provided buffer. If a callback keeps strings elsewhere, nscd can corrupt memory while handling the cache. The source notes the flaw was introduced in glibc 2.15 when the cache was added to nscd, and that it is only present in the nscd binary. Siemens ties this to five affected product identifiers and lists no available fix.
Defensive priority
Medium. The supplied CVSS vector is AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L, which points to local access and limited impact, but the affected Siemens products have no fix in the advisory and rely on compensating controls.
Recommended defensive actions
- Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only.
- Only build and run applications from trusted sources on affected devices.
- Treat the listed SIMATIC S7-1500 CPU models as affected until Siemens provides a corrective update or revised guidance.
- Track Siemens ProductCERT and CISA advisory updates for changes to remediation status.
- Use compensating controls and maintenance planning to reduce exposure in OT environments that rely on the affected subsystem.
Evidence notes
Source evidence comes from Siemens ProductCERT advisory SSA-082556 as republished in CISA CSAF advisory ICSA-25-162-05. The source item lists the affected SIMATIC S7-1500 CPU product names, the nscd/netgroup cache memory-corruption description, the CVSS 3.1 vector, and a remediation entry stating that no fix is currently available. PublishedAt is 2025-06-10 and ModifiedAt is 2026-05-14; those dates are used here for advisory timing context only.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-33602 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-33602
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-33602 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-33602
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.