PatchSiren cyber security CVE debrief
CVE-2024-37370 Siemens CVE debrief
CVE-2024-37370 describes an integrity flaw in MIT Kerberos 5 (krb5) before 1.21.3. An attacker can alter the plaintext Extra Count field in a confidential GSS krb5 wrap token, which can make the unwrapped token appear truncated to the application. Siemens’ advisory maps this CVE to several SIMATIC S7-1500 CPU family products and states that no fix is currently available, so affected deployments should rely on compensating controls.
- Vendor
- Siemens
- Product
- SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Organizations operating the Siemens SIMATIC S7-1500 CPU family listed in the advisory, especially environments using the additional GNU/Linux subsystem, GSS/Kerberos-protected application flows, or other services that process krb5 wrap tokens. OT security teams and asset owners should care because Siemens’ advisory provides only mitigations, not a fix.
Technical summary
The flaw is in the handling of confidential GSS krb5 wrap tokens. By modifying the plaintext Extra Count field, an attacker can influence how the receiving application interprets the decrypted token, causing it to appear truncated. The supplied CVSS vector emphasizes network attackability with no privileges or user interaction required, and the impact is centered on integrity and availability rather than confidentiality.
Defensive priority
High for any affected Siemens product in service, because the advisory lists no fixed version and recommends only compensating controls. Prioritize exposure reduction, subsystem access restriction, and validation of any Kerberos-dependent application paths.
Recommended defensive actions
- Identify whether any of the five Siemens product variants listed in the advisory are deployed in your environment.
- Limit access to the interactive shell of the additional GNU/Linux subsystem to trusted personnel only, as Siemens recommends.
- Only build and run applications from trusted sources on affected systems, as Siemens recommends.
- Treat the affected systems as requiring compensating controls until Siemens provides a fix or a supported update path.
- Review GSS/Kerberos-dependent services for anomalous token handling and application errors consistent with truncated protected data.
- Use standard OT network segmentation and least-privilege access to reduce the chance that an attacker can reach the affected paths.
Evidence notes
The supplied corpus ties CVE-2024-37370 to Siemens advisory ICSA-25-162-05 / SSA-082556, published on 2025-06-10 and updated through 2026-05-14. The vulnerability description is explicitly attributed to MIT Kerberos 5 before 1.21.3. Siemens lists five affected SIMATIC S7-1500 CPU family product variants and includes mitigations, with no fix currently available. The corpus does not indicate KEV listing or known ransomware use.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-37370 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-37370
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-37370 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-37370
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.