PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-47195 Siemens CVE debrief

CVE-2024-47195 is a local privilege escalation vulnerability in Siemens ModelSim and Questa, published 2024-10-08. The issue stems from gdb.exe loading a specific executable from the current working directory, enabling authenticated local attackers to inject arbitrary code when administrators launch gdb.exe from user-writable directories. With CVSS 6.7 (Medium), this requires local access, low privileges, and user interaction under high attack complexity. The vendor has released updates in V2024.3 or later to address this. Organizations should prioritize patching and restrict local access to application servers hosting these tools.

Vendor
Siemens
Product
ModelSim
CVSS
MEDIUM 6.7
CISA KEV
Not listed in stored evidence
Original CVE published
2024-10-08
Original CVE updated
2025-05-06
Advisory published
2024-10-08
Advisory updated
2025-05-06

Who should care

Organizations using Siemens ModelSim or Questa for hardware design and verification, particularly in shared or multi-user environments where developers with varying privilege levels access simulation tools. System administrators responsible for EDA tool deployments and security teams in semiconductor, aerospace, defense, and industrial sectors relying on these tools for FPGA/ASIC development.

Technical summary

The vulnerability exists in gdb.exe within Siemens ModelSim and Questa simulation tools. When gdb.exe is launched from a user-writable directory, it loads a specific executable from the current working directory without proper path validation. This behavior allows an authenticated local attacker with low privileges to place a malicious executable in the working directory, which gets loaded when an administrator or elevated process launches gdb.exe. The attack requires user interaction and high complexity due to the need for specific timing and directory conditions, but successful exploitation yields high impact across confidentiality, integrity, and availability.

Defensive priority

medium

Recommended defensive actions

  • Update Siemens ModelSim and Questa to V2024.3 or later to remediate the gdb.exe current working directory loading vulnerability
  • Harden application servers to prevent local access by untrusted personnel as a defense-in-depth measure
  • Review and restrict directory permissions to prevent execution from user-writable locations when elevated privilege processes are launched
  • Monitor for anomalous gdb.exe execution from non-standard working directories in environments running ModelSim or Questa

Evidence notes

Vulnerability description and remediation details sourced from CISA CSAF advisory ICSA-24-284-05, with vendor fix confirmed by Siemens security advisory SSA-426509. CVSS vector AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H indicates local attack vector with high complexity requiring user interaction.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-47195 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-47195

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-47195 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-47195

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-284-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-426509.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-426509.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-284-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.