PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-47046 Siemens CVE debrief

A memory corruption vulnerability exists in Siemens Simcenter Femap when parsing specially crafted BDF (Bulk Data File) files. The flaw, published December 10, 2024, could allow an attacker to execute arbitrary code within the context of the current process. The vulnerability affects multiple versions: V2306, V2401, and V2406. Siemens has released a vendor fix for V2406 users through the Femap 2406 Nastran Updates, while V2306 and V2401 currently have no patch available. CISA and Siemens recommend defensive measures including avoiding untrusted BDF files until patches can be applied.

Vendor
Siemens
Product
Simcenter Nastran 2306
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-12-10
Original CVE updated
2024-12-10
Advisory published
2024-12-10
Advisory updated
2024-12-10

Who should care

Engineering organizations using Simcenter Femap for finite element analysis, particularly in aerospace, automotive, and industrial manufacturing sectors. Security teams protecting OT/ICS environments with engineering workstations. Organizations with Nastran-based simulation workflows dependent on BDF file exchange.

Technical summary

The vulnerability stems from improper memory handling during parsing of BDF (Bulk Data File) format files in Simcenter Femap, a finite element analysis pre- and post-processor. BDF files are commonly used in Nastran-based engineering workflows for structural analysis. The memory corruption condition can be triggered when a user opens a maliciously crafted BDF file, leading to arbitrary code execution in the context of the running process. The CVSS 3.1 score of 7.8 (HIGH) reflects significant confidentiality, integrity, and availability impacts, though exploitation requires local access and user interaction. The attack complexity is low, and no privileges are required, making social engineering or supply chain compromise viable attack vectors.

Defensive priority

HIGH

Recommended defensive actions

  • Apply Siemens Femap 2406 Nastran Updates to V2406 installations as soon as possible
  • For V2306 and V2401 deployments, implement strict controls to prevent opening of untrusted BDF files
  • Restrict user permissions to limit impact of potential exploitation
  • Monitor for suspicious BDF file handling in engineering workflows
  • Establish asset inventory to identify affected Simcenter Femap installations across versions

Evidence notes

CVE published and modified 2024-12-10 per official record. CISA ICS advisory ICSA-24-347-06 issued same date. Siemens SSA-881356 published concurrently. CVSS 3.1 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H confirms local attack vector requiring user interaction.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-47046 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-47046

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-47046 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-47046

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-284-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-852501.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-852501.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-284-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.