PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-35292 Siemens CVE debrief

A vulnerability in Siemens SIMATIC S7-200 SMART CPU devices allows attackers to exploit predictable IP ID sequence numbers, potentially leading to denial of service conditions. The affected devices use predictable IP ID sequence numbers, making them susceptible to attacks that rely on this predictability as their base method. This vulnerability has a CVSS 3.1 score of 8.2 (HIGH severity) and was published on June 11, 2024. Siemens has indicated that currently no fix is planned for this vulnerability.

Vendor
Siemens
Product
SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0)
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-11
Original CVE updated
2024-06-11
Advisory published
2024-06-11
Advisory updated
2024-06-11

Who should care

Organizations operating Siemens SIMATIC S7-200 SMART programmable logic controllers in industrial control system environments, particularly those with internet-facing or broadly networked deployments. Asset owners in manufacturing, water/wastewater, energy, and other critical infrastructure sectors using these devices should prioritize network segmentation and access controls.

Technical summary

The vulnerability stems from the use of predictable IP ID sequence numbers in Siemens SIMATIC S7-200 SMART CPU devices. IP ID fields are used in IP packet fragmentation; predictable values enable attacks such as idle scanning, OS fingerprinting, and denial of service through IP spoofing and fragmentation attacks. The CVSS score of 8.2 reflects high availability impact with network accessibility and low attack complexity. Eighteen distinct CPU models across CR, SR, and ST series are affected. Siemens has classified this as 'no fix planned,' indicating that affected organizations must rely on compensating controls rather than patches.

Defensive priority

HIGH

Recommended defensive actions

  • Restrict network access to affected Siemens SIMATIC S7-200 SMART CPU devices using strict access control mechanisms
  • Segment affected devices from untrusted networks
  • Monitor network traffic for anomalous patterns targeting IP ID sequence prediction
  • Apply defense-in-depth strategies per CISA ICS recommended practices
  • Review Siemens Security Advisory SSA-481506 for additional vendor guidance

Evidence notes

The vulnerability description and affected product list are derived from CISA CSAF advisory ICSA-24-165-02, which references Siemens Security Advisory SSA-481506. The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:T/RC:C indicates network attack vector, low attack complexity, no privileges required, no user interaction, with high availability impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-35292 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-35292

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-35292 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35292

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-481506.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-481506.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-481506.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-481506.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.