PatchSiren cyber security CVE debrief
CVE-2024-45386 Siemens CVE debrief
CVE-2024-45386 is a session-management weakness in several Siemens products where user logout does not correctly invalidate the session. According to the advisory, an attacker who already obtained a valid session token by other means could reuse that token after logout. The issue was publicly disclosed on 2025-02-11 and later revised on 2025-05-06 for typo fixes only.
- Vendor
- Siemens
- Product
- SIMATIC PCS neo V4.0
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-11
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-02-11
- Advisory updated
- 2025-05-06
Who should care
OT/ICS operators, administrators, and security teams responsible for Siemens SIMATIC PCS neo, SIMOCODE ES, SIRIUS Safety ES, SIRIUS Soft Starter ES, and TIA Administrator deployments.
Technical summary
The advisory states that affected products do not correctly invalidate user sessions upon logout. That means a previously issued session token may remain usable after the user believes the session has ended. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (8.8 HIGH). The source advisory lists affected Siemens products and provides version-specific remediation, including one product family with no fix currently planned.
Defensive priority
High
Recommended defensive actions
- Upgrade SIMOCODE ES V19, SIRIUS Safety ES V19 (TIA Portal), and SIRIUS Soft Starter ES V19 (TIA Portal) to V19 Update 1 or later.
- Upgrade TIA Administrator to v3.0.4 or later.
- Upgrade SIMATIC PCS neo V4.1 to V4.1 Update 2 or later, and SIMATIC PCS neo V5.0 to V5.0 Update 1 or later.
- For SIMATIC PCS neo V4.0, note that the advisory states no fix is currently planned; apply compensating controls and monitor Siemens advisories.
- After logout, close the browser/client and remove any locally stored session tokens, as recommended by the advisory.
- If token exposure is suspected, treat the session as potentially reusable and investigate affected accounts and endpoints.
Evidence notes
The Siemens/CISA advisory text explicitly says affected products do not correctly invalidate user sessions upon logout and that a remote unauthenticated attacker who has obtained the session token by other means could reuse a legitimate user's session even after logout. The supplied advisory metadata lists seven affected products, includes product-specific remediations, and records that the 2025-05-06 modification was a revision fixing typos. The enrichment supplied for this record indicates no Known Exploited Vulnerabilities (KEV) listing.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-45386 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-45386
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-45386 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-45386
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-13.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-342348.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-342348.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-13
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.