PatchSiren cyber security CVE debrief
CVE-2024-37998 Siemens CVE debrief
A critical authentication bypass vulnerability in Siemens SICAM products allows unauthorized administrative access when auto login is enabled. The flaw permits password reset of administrative accounts without knowledge of the current password, enabling complete system compromise.
- Vendor
- Siemens
- Product
- CPCI85 Central Processing/Communication
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-07-22
- Original CVE updated
- 2024-07-22
- Advisory published
- 2024-07-22
- Advisory updated
- 2024-07-22
Who should care
Organizations operating Siemens SICAM CPCI85 or SICORE systems in electric power grid, industrial control, or critical infrastructure environments. Security teams responsible for OT/ICS asset protection and compliance with NERC CIP or similar critical infrastructure standards. System integrators and operators of Siemens energy automation products.
Technical summary
CVE-2024-37998 is a critical authentication bypass vulnerability affecting Siemens SICAM products including CPCI85 Central Processing/Communication and SICORE Base system. When auto login is enabled, administrative account passwords can be reset without requiring knowledge of the current password. This allows unauthenticated attackers to gain full administrative access to affected applications. The vulnerability is rated CVSS 3.1 9.8 (Critical) with attack vector network, attack complexity low, and no privileges required. Siemens has released firmware updates to address the issue: CPCI85 V5.40 and SICORE V1.4.0. CISA recommends disabling auto login as an immediate mitigation pending patching.
Defensive priority
critical
Recommended defensive actions
- Disable auto login feature immediately on affected Siemens SICAM systems per CISA and Siemens guidance
- Apply vendor firmware updates: CPCI85 to V5.40 or later via CP-8031/CP-8050 Package V5.40
- Apply vendor firmware updates: SICORE to V1.4.0 or later via SICAM 8 Software Solution Package V5.40
- Review administrative account activity for unauthorized access indicators
- Implement network segmentation for ICS/OT environments per CISA recommended practices
- Monitor for anomalous authentication events on affected systems
Evidence notes
CISA ICS advisory ICSA-24-207-01 published 2024-07-22 documents this vulnerability in Siemens SICAM products. The advisory confirms affected products include CPCI85 Central Processing/Communication and SICORE Base system. Siemens ProductCERT advisory SSA-071402 provides vendor remediation guidance. CVSS 3.1 score of 9.8 reflects network exploitable, low complexity attack with no privileges required.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-37998 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-37998
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-37998 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-37998
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-207-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-071402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-071402.html
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/pdf/ssa-071402.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/txt/ssa-071402.txt
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-207-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.