PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-36398 Siemens CVE debrief

A local privilege escalation vulnerability in Siemens SINEC NMS allows authenticated users to execute operating system commands with SYSTEM-level privileges. The affected application runs a subset of services as NT AUTHORITY SYSTEM, creating an attack surface where a local attacker with existing access can elevate privileges to execute arbitrary OS commands. This vulnerability requires local access and low attack complexity, with high impact on confidentiality, integrity, and availability. Siemens has released version 3.0 to address this issue.

Vendor
Siemens
Product
SINEC NMS
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-08-13
Original CVE updated
2024-08-13
Advisory published
2024-08-13
Advisory updated
2024-08-13

Who should care

Organizations operating Siemens SINEC NMS in industrial control system environments, particularly those with multi-user Windows hosts or shared administrative access. Critical infrastructure operators, manufacturing facilities, and utilities using SINEC NMS for network management should prioritize patching due to the high impact of local privilege escalation in OT environments where lateral movement can have significant operational consequences.

Technical summary

Siemens SINEC NMS, a network management system for industrial environments, executes certain services with NT AUTHORITY SYSTEM privileges. This misconfiguration allows any authenticated local user to leverage these overprivileged services to execute arbitrary operating system commands with elevated privileges. The vulnerability is rated CVSS 3.1 7.8 HIGH with attack vector LOCAL, attack complexity LOW, and privileges required LOW. Impact is rated HIGH for confidentiality, integrity, and availability. Siemens remediated this in version 3.0 by adjusting service privilege levels.

Defensive priority

HIGH

Recommended defensive actions

  • Apply vendor fix: Update Siemens SINEC NMS to version 3.0 or later
  • Restrict local access to SINEC NMS hosts to authorized administrators only
  • Monitor for anomalous process execution and privilege escalation attempts on SINEC NMS systems
  • Review service account configurations and apply principle of least privilege where possible
  • Validate backup and recovery procedures before applying updates to critical OT infrastructure

Evidence notes

CISA published advisory ICSA-24-228-06 on 2024-08-13, confirming Siemens SINEC NMS executes services as NT AUTHORITY SYSTEM. Siemens issued security advisory SSA-784301 with remediation guidance. CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H confirms local attack vector with high impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-36398 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-36398

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-36398 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-36398

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-228-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-784301.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-784301.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-228-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.